← Vulnerability feed

Vulnerability record · CVE-2021-43942 · published 4 January 2022

CVE-2021-43942: Atlassian Jira Server reflected XSS in collectors template endpoint

Atlassian · Jira Server

Jira Server and Data Center contain a reflected cross-site scripting flaw in the /rest/collectors/1.0/template/custom endpoint, allowing injection of arbitrary HTML or JavaScript. An attacker must lure a victim to a malicious site to trigger it, so exploitation depends on user interaction rather than direct server compromise.

6.1 CVSS 3.1 Medium EPSS 55% · top 1.0% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. To exploit this issue, the attacker must trick a user into visiting a malicious website. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS rates it medium at 6.1 and exploitation requires user interaction, but the high EPSS percentile and unauthenticated network reachability warrant prompt patching.

What it is

Jira Server and Data Center contain a reflected cross-site scripting flaw in the /rest/collectors/1.0/template/custom endpoint, allowing injection of arbitrary HTML or JavaScript. An attacker must lure a victim to a malicious site to trigger it, so exploitation depends on user interaction rather than direct server compromise.

Impact

Successful exploitation lets the attacker run script in the victim's Jira session context, potentially stealing session data or performing actions as the user. The scope change in the CVSS vector indicates impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network via the REST collectors template endpoint with no authentication required, but the victim must be tricked into visiting a malicious website, so user interaction is required.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, though EPSS is high at roughly 0.55 (99th percentile), suggesting elevated likelihood of attempted exploitation.

What to do

  • Upgrade Jira Server and Data Center to version 8.13.15 or later, or 8.20.3 or later for the 8.14.x line.
  • If immediate patching is not possible, restrict or monitor access to the /rest/collectors/1.0/template/custom endpoint.
  • Deploy a web application firewall rule to block script payloads targeting the collectors template endpoint.
  • Educate users about phishing and malicious links, since exploitation requires tricking a user into visiting an attacker-controlled site.

Detection

  • Review web and proxy logs for requests to /rest/collectors/1.0/template/custom containing script tags or encoded HTML in parameters.
  • Monitor for anomalous outbound requests or referrer patterns consistent with a user being redirected from an external malicious site into Jira.
  • Alert on unexpected JavaScript execution or DOM changes reported by browser security tooling on Jira pages.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.atlassian.com/browse/JRASERVER-73068 Issue TrackingVendor Advisory
https://jira.atlassian.com/browse/JRASERVER-73068 Issue TrackingVendor Advisory

Track CVE-2021-43942 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-11581Atlassian Jira Server and Data Center server-side template injectionJira Server and Data Center contain a server-side template injection flaw in the ContactAdministrators and SendBulkMail actions. An attacker can inje…KEVEPSS 85%analysed5.3CVE-2021-26086Atlassian Jira Server and Data Center path traversal file readJira Server and Data Center contain a path traversal flaw in the /WEB-INF/web.xml endpoint that lets remote attackers read particular files. The affe…KEVEPSS 100%analysed9.8CVE-2022-26136Atlassian bamboo improper authentication vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…EPSS 5.4%9.8CVE-2022-0540Atlassian Jira Seraph authentication bypass via crafted HTTP requestJira Server, Data Center and Jira Service Management contain an authentication bypass in the Seraph component, reachable by sending a specially craft…EPSS 88%analysed8.8CVE-2024-21683Atlassian Confluence Data Center and Server code injection RCEConfluence Data Center and Server contain a code injection flaw introduced in version 5.2 that allows an authenticated attacker to execute arbitrary …EPSS 88%analysed8.8CVE-2022-26137Atlassian bamboo origin validation error vulnerabilityA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the a…EPSS 2.3%8.7CVE-2025-22167Atlassian jira data center path traversal vulnerabilityThis High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Sof…EPSS 0.50%8.1CVE-2019-8443Atlassian jira improper authentication vulnerabilityThe ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows …EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2021-43942), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.