Atlassian Jira vulnerabilities

155 known vulnerabilities affecting atlassian/jira.

Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3

Vulnerabilities

Page 3 of 8
CVE-2020-29451MEDIUMCVSS 4.3fixed in 8.5.112021-02-15
CVE-2020-29451 [MEDIUM] CVE-2020-29451: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.
nvd
CVE-2020-36234MEDIUMCVSS 4.8fixed in 8.5.112021-02-15
CVE-2020-36234 [MEDIUM] CWE-79 CVE-2020-36234: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
nvd
CVE-2020-36235MEDIUMCVSS 5.3fixed in 8.13.22021-02-15
CVE-2020-36235 [MEDIUM] CVE-2020-36235: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
nvd
CVE-2020-36231MEDIUMCVSS 4.3fixed in 8.5.102021-02-02
CVE-2020-36231 [MEDIUM] CWE-639 CVE-2020-36231: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metada Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
nvd
CVE-2020-14185MEDIUMCVSS 5.3fixed in 7.13.182020-10-15
CVE-2020-14185 [MEDIUM] CWE-862 CVE-2020-14185: Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2.
nvd
CVE-2020-14184MEDIUMCVSS 5.4fixed in 8.5.92020-10-12
CVE-2020-14184 [MEDIUM] CWE-79 CVE-2020-14184: Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaSc Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected versions are before 8.5.9, from version 8.6.0 before 8.12.3, and from version 8.13.0 before 8.13.1.
nvd
CVE-2020-14183MEDIUMCVSS 4.3fixed in 7.13.18≥ 8.0.0, < 8.5.9+1 more2020-10-06
CVE-2020-14183 [MEDIUM] CWE-200 CVE-2020-14183: Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) priv Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 befor
nvd
CVE-2020-14181MEDIUMCVSS 5.3PoCfixed in 7.13.62020-09-17
CVE-2020-14181 [MEDIUM] CWE-200 CVE-2020-14181: Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerat Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0.
nvd
CVE-2020-14178HIGHCVSS 7.5fixed in 7.13.72020-09-01
CVE-2020-14178 [HIGH] CVE-2020-14178: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate proje Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.
nvd
CVE-2019-20898HIGHCVSS 7.5fixed in 8.8.02020-07-13
CVE-2019-20898 [HIGH] CVE-2019-20898: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitiv Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.
nvd
CVE-2019-20899MEDIUMCVSS 5.3fixed in 8.5.42020-07-13
CVE-2019-20899 [MEDIUM] CVE-2019-20899: The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
nvd
CVE-2019-20897MEDIUMCVSS 6.5fixed in 8.5.42020-07-13
CVE-2019-20897 [MEDIUM] CWE-434 CVE-2019-20897: The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remot The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2019-20901MEDIUMCVSS 6.1fixed in 8.5.22020-07-13
CVE-2019-20901 [MEDIUM] CWE-601 CVE-2019-20901: The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 all The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter.
nvd
CVE-2020-14174MEDIUMCVSS 4.3fixed in 7.13.162020-07-13
CVE-2020-14174 [MEDIUM] CWE-639 CVE-2020-14174: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version
nvd
CVE-2020-14172CRITICALCVSS 9.8fixed in 7.13.0≥ 8.0.0, < 8.5.0+1 more2020-07-03
CVE-2020-14172 [CRITICAL] CWE-502 CVE-2020-14172: This issue exists to document that a security improvement in the way that Jira Server and Data Cente This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers to achieve remote code execution via insecure deserialization, if the
nvd
CVE-2019-20418MEDIUMCVSS 6.5fixed in 8.8.02020-07-03
CVE-2019-20418 [MEDIUM] CVE-2019-20418: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users f Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0.
nvd
CVE-2020-14173MEDIUMCVSS 5.4fixed in 8.5.42020-07-03
CVE-2020-14173 [MEDIUM] CWE-79 CVE-2020-14173: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2020-14167HIGHCVSS 7.5fixed in 7.13.142020-07-01
CVE-2020-14167 [HIGH] CVE-2020-14167: The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the application's availability via an Denial of Service (DoS) vulnerability.
nvd
CVE-2019-20408MEDIUMCVSS 5.3fixed in 8.7.02020-07-01
CVE-2019-20408 [MEDIUM] CWE-918 CVE-2019-20408: The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attacke The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
nvd
CVE-2020-4025MEDIUMCVSS 4.8fixed in 8.5.52020-07-01
CVE-2020-4025 [MEDIUM] CWE-79 CVE-2020-4025: The attachment download resource in Atlassian Jira Server and Data Center The attachment download re The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a
nvd