Atlassian Jira vulnerabilities
155 known vulnerabilities affecting atlassian/jira.
Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3
Vulnerabilities
Page 3 of 8
CVE-2020-29451MEDIUMCVSS 4.3fixed in 8.5.112021-02-15
CVE-2020-29451 [MEDIUM] CVE-2020-29451: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.
nvd
CVE-2020-36234MEDIUMCVSS 4.8fixed in 8.5.112021-02-15
CVE-2020-36234 [MEDIUM] CWE-79 CVE-2020-36234: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
nvd
CVE-2020-36235MEDIUMCVSS 5.3fixed in 8.13.22021-02-15
CVE-2020-36235 [MEDIUM] CVE-2020-36235: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
nvd
CVE-2020-36231MEDIUMCVSS 4.3fixed in 8.5.102021-02-02
CVE-2020-36231 [MEDIUM] CWE-639 CVE-2020-36231: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metada
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
nvd
CVE-2020-14185MEDIUMCVSS 5.3fixed in 7.13.182020-10-15
CVE-2020-14185 [MEDIUM] CWE-862 CVE-2020-14185: Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2.
nvd
CVE-2020-14184MEDIUMCVSS 5.4fixed in 8.5.92020-10-12
CVE-2020-14184 [MEDIUM] CWE-79 CVE-2020-14184: Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaSc
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected versions are before 8.5.9, from version 8.6.0 before 8.12.3, and from version 8.13.0 before 8.13.1.
nvd
CVE-2020-14183MEDIUMCVSS 4.3fixed in 7.13.18≥ 8.0.0, < 8.5.9+1 more2020-10-06
CVE-2020-14183 [MEDIUM] CWE-200 CVE-2020-14183: Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) priv
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 befor
nvd
CVE-2020-14181MEDIUMCVSS 5.3PoCfixed in 7.13.62020-09-17
CVE-2020-14181 [MEDIUM] CWE-200 CVE-2020-14181: Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerat
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0.
nvd
CVE-2020-14178HIGHCVSS 7.5fixed in 7.13.72020-09-01
CVE-2020-14178 [HIGH] CVE-2020-14178: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate proje
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.
nvd
CVE-2019-20898HIGHCVSS 7.5fixed in 8.8.02020-07-13
CVE-2019-20898 [HIGH] CVE-2019-20898: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitiv
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.
nvd
CVE-2019-20899MEDIUMCVSS 5.3fixed in 8.5.42020-07-13
CVE-2019-20899 [MEDIUM] CVE-2019-20899: The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
nvd
CVE-2019-20897MEDIUMCVSS 6.5fixed in 8.5.42020-07-13
CVE-2019-20897 [MEDIUM] CWE-434 CVE-2019-20897: The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remot
The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2019-20901MEDIUMCVSS 6.1fixed in 8.5.22020-07-13
CVE-2019-20901 [MEDIUM] CWE-601 CVE-2019-20901: The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 all
The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter.
nvd
CVE-2020-14174MEDIUMCVSS 4.3fixed in 7.13.162020-07-13
CVE-2020-14174 [MEDIUM] CWE-639 CVE-2020-14174: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version
nvd
CVE-2020-14172CRITICALCVSS 9.8fixed in 7.13.0≥ 8.0.0, < 8.5.0+1 more2020-07-03
CVE-2020-14172 [CRITICAL] CWE-502 CVE-2020-14172: This issue exists to document that a security improvement in the way that Jira Server and Data Cente
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers to achieve remote code execution via insecure deserialization, if the
nvd
CVE-2019-20418MEDIUMCVSS 6.5fixed in 8.8.02020-07-03
CVE-2019-20418 [MEDIUM] CVE-2019-20418: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users f
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0.
nvd
CVE-2020-14173MEDIUMCVSS 5.4fixed in 8.5.42020-07-03
CVE-2020-14173 [MEDIUM] CWE-79 CVE-2020-14173: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote
The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2020-14167HIGHCVSS 7.5fixed in 7.13.142020-07-01
CVE-2020-14167 [HIGH] CVE-2020-14167: The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0
The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the application's availability via an Denial of Service (DoS) vulnerability.
nvd
CVE-2019-20408MEDIUMCVSS 5.3fixed in 8.7.02020-07-01
CVE-2019-20408 [MEDIUM] CWE-918 CVE-2019-20408: The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attacke
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
nvd
CVE-2020-4025MEDIUMCVSS 4.8fixed in 8.5.52020-07-01
CVE-2020-4025 [MEDIUM] CWE-79 CVE-2020-4025: The attachment download resource in Atlassian Jira Server and Data Center The attachment download re
The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a
nvd