Atlassian Jira vulnerabilities
155 known vulnerabilities affecting atlassian/jira.
Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3
Vulnerabilities
Page 1 of 8
CVE-2019-8451P2MEDIUMCVSS 6.5ExploitedPoC≥ unspecified, < 8.4.02019-09-11
CVE-2019-8451 [MEDIUM] CWE-918 CVE-2019-8451: The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attacke
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
nvd
CVE-2019-8442P1HIGHCVSS 7.5ExploitedPoCfixed in 7.13.4≥ unspecified, < 7.13.4+4 more2019-05-22
CVE-2019-8442 [HIGH] CVE-2019-8442: The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 b
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
nvd
CVE-2019-8446P1MEDIUMCVSS 5.3ExploitedPoC≥ unspecified, < 8.3.22019-08-23
CVE-2019-8446 [MEDIUM] CWE-863 CVE-2019-8446: The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enu
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
nvd
CVE-2010-1164P2MEDIUMCVSS 4.3Exploitedv3.12v3.12.1+12 more2010-04-20
CVE-2010-1164 [MEDIUM] CWE-79 CVE-2010-1164: Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote
Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) element or (2) defaultColor parameter to the Colour Picker page; the (3) formName parameter, (4) element parameter, or (5) full name field to the User Picker page; the (6) formName parameter, (7
nvd
CVE-2010-1165P2CRITICALCVSS 9.0Exploitedv3.12v3.12.1+12 more2010-04-20
CVE-2010-1165 [CRITICAL] CWE-94 CVE-2010-1165: Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code
Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka attachments), (2) index (aka indexing), or (3) backup path and then uploading a file, as exploited in the wild in April 2010.
nvd
CVE-2012-2926P2CRITICALCVSS 9.1PoCfixed in 5.0.12012-05-22
CVE-2012-2926 [CRITICAL] CVE-2012-2926: Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; Fish
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of
nvd
CVE-2020-14181P2MEDIUMCVSS 5.3PoCfixed in 7.13.62020-09-17
CVE-2020-14181 [MEDIUM] CWE-200 CVE-2020-14181: Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerat
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0.
nvd
CVE-2020-36289P2MEDIUMCVSS 5.3PoCfixed in 8.5.132021-05-12
CVE-2020-36289 [MEDIUM] CWE-863 CVE-2020-36289: Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerat
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
nvd
CVE-2019-8449P3MEDIUMCVSS 5.3PoCfixed in 8.4.0≥ unspecified, < 8.4.02019-09-11
CVE-2019-8449 [MEDIUM] CWE-306 CVE-2019-8449: The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers t
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
nvd
CVE-2017-5983P2CRITICALCVSS 9.8PoCv4.2.4v4.3+64 more2017-04-10
CVE-2017-5983 [CRITICAL] CWE-502 CVE-2017-5983: The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parse
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
nvd
CVE-2019-3403P3MEDIUMCVSS 5.3PoCfixed in 7.13.3≥ unspecified, < 7.13.3+4 more2019-05-22
CVE-2019-3403 [MEDIUM] CWE-863 CVE-2019-3403: The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before v
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
nvd
CVE-2018-5230P3MEDIUMCVSS 6.1PoCfixed in 7.6.6≥ unspecified, < 7.6.6+6 more2018-05-14
CVE-2018-5230 [MEDIUM] CWE-79 CVE-2018-5230: The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4,
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value
nvd
CVE-2018-20824P3MEDIUMCVSS 6.1PoCfixed in 7.13.1≥ unspecified, < 7.13.12019-05-03
CVE-2018-20824 [MEDIUM] CWE-79 CVE-2018-20824: The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitr
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
nvd
CVE-2014-2314P3MEDIUMCVSS 4.3PoC≤ 6.0.3v6.0+2 more2014-03-09
CVE-2014-2314 [MEDIUM] CWE-22 CVE-2014-2314: Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allow
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.
nvd
CVE-2019-3401P3MEDIUMCVSS 5.3PoCfixed in 7.13.3≥ unspecified, < 7.13.3+2 more2019-05-22
CVE-2019-3401 [MEDIUM] CWE-863 CVE-2019-3401: The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
nvd
CVE-2019-3402P3MEDIUMCVSS 6.1PoCfixed in 7.13.3≥ unspecified, < 7.13.3+2 more2019-05-22
CVE-2019-3402 [MEDIUM] CWE-79 CVE-2019-3402: The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before v
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
nvd
CVE-2020-14172P2CRITICALCVSS 9.8fixed in 7.13.0≥ 8.0.0, < 8.5.0+1 more2020-07-03
CVE-2020-14172 [CRITICAL] CWE-502 CVE-2020-14172: This issue exists to document that a security improvement in the way that Jira Server and Data Cente
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers to achieve remote code execution via insecure deserialization, if the
nvd
CVE-2021-26078P3MEDIUMCVSS 6.1PoCfixed in 8.5.142021-06-07
CVE-2021-26078 [MEDIUM] CWE-79 CVE-2021-26078: The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
nvd
CVE-2019-20409P3CRITICALCVSS 9.8fixed in 8.8.02020-06-23
CVE-2019-20409 [CRITICAL] CWE-74 CVE-2019-20409: The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to vers
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
nvd
CVE-2017-18113P3HIGHCVSS 8.8fixed in 8.18.12021-08-02
CVE-2017-18113 [HIGH] CWE-94 CVE-2017-18113: The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 al
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code Execution (RCE) vulnerability. The vulnerability allowed for various problematic OSWorkflow classes to be used as pa
nvd
1 / 8Next →