Atlassian Jira vulnerabilities
155 known vulnerabilities affecting atlassian/jira.
Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3
Vulnerabilities
Page 3 of 8
CVE-2019-20897P4MEDIUMCVSS 6.5fixed in 8.5.42020-07-13
CVE-2019-20897 [MEDIUM] CWE-434 CVE-2019-20897: The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remot
The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2017-18101P4MEDIUMCVSS 6.5fixed in 7.6.5≥ unspecified, < 7.6.5+4 more2018-04-10
CVE-2017-18101 [MEDIUM] CWE-284 CVE-2017-18101: Various administrative external system import resources in Atlassian JIRA Server (including JIRA Cor
Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow remote attackers to run import operations and to determine if an internal service exists through missing permissio
nvd
CVE-2007-6619P4HIGHCVSS 7.5≤ 3.122008-01-03
CVE-2007-6619 [HIGH] CWE-264 CVE-2007-6619: The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup
The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows remote attackers to change the default language.
nvd
CVE-2016-4319P4HIGHCVSS 8.8≤ 7.1.82017-04-10
CVE-2016-4319 [HIGH] CWE-352 CVE-2016-4319: Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
nvd
CVE-2021-26069P4MEDIUMCVSS 5.3fixed in 8.5.112021-03-22
CVE-2021-26069 [MEDIUM] CWE-74 CVE-2021-26069: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations API endpoint. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and
nvd
CVE-2019-20899P4MEDIUMCVSS 5.3fixed in 8.5.42020-07-13
CVE-2019-20899 [MEDIUM] CVE-2019-20899: The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
nvd
CVE-2019-14995P4MEDIUMCVSS 5.3≥ unspecified, < 8.4.02019-09-11
CVE-2019-14995 [MEDIUM] CWE-863 CVE-2019-14995: The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.
nvd
CVE-2020-14185P4MEDIUMCVSS 5.3fixed in 7.13.182020-10-15
CVE-2020-14185 [MEDIUM] CWE-862 CVE-2020-14185: Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2.
nvd
CVE-2018-13391P4MEDIUMCVSS 5.3fixed in 7.6.8≥ unspecified, < 7.6.8+10 more2018-08-28
CVE-2018-13391 [MEDIUM] CWE-200 CVE-2018-13391: The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before v
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain th
nvd
CVE-2020-36238P4MEDIUMCVSS 5.3fixed in 8.5.132021-04-01
CVE-2020-36238 [MEDIUM] CWE-863 CVE-2020-36238: The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions check.
nvd
CVE-2021-26081P4MEDIUMCVSS 5.3fixed in 8.5.142021-07-20
CVE-2021-26081 [MEDIUM] CVE-2021-26081: REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 bef
REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to enumerate usernames via a Sensitive Data Exposure vulnerability in the `/rest/api/latest/user/avatar/temporary` endpoint.
nvd
CVE-2012-2928P4MEDIUMCVSS 6.4≤ 5.0.02012-05-22
CVE-2012-2928 [MEDIUM] CWE-264 CVE-2012-2928: The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
nvd
CVE-2019-20418P4MEDIUMCVSS 6.5fixed in 8.8.02020-07-03
CVE-2019-20418 [MEDIUM] CVE-2019-20418: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users f
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0.
nvd
CVE-2020-36235P4MEDIUMCVSS 5.3fixed in 8.13.22021-02-15
CVE-2020-36235 [MEDIUM] CVE-2020-36235: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
nvd
CVE-2021-39118P4MEDIUMCVSS 5.3fixed in 8.19.02021-09-14
CVE-2021-39118 [MEDIUM] CVE-2021-39118: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the us
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0.
nvd
CVE-2021-39125P4MEDIUMCVSS 5.3fixed in 8.5.102021-09-14
CVE-2021-39125 [MEDIUM] CVE-2021-39125: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to disco
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
nvd
CVE-2019-20101P4MEDIUMCVSS 5.3fixed in 8.13.3v82021-09-14
CVE-2019-20101 [MEDIUM] CVE-2019-20101: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist//check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
nvd
CVE-2021-39127P4MEDIUMCVSS 5.3fixed in 8.5.102021-10-21
CVE-2021-39127 [MEDIUM] CVE-2021-39127: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the q
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
nvd
CVE-2020-36237P4MEDIUMCVSS 5.3fixed in 8.15.02021-02-15
CVE-2020-36237 [MEDIUM] CVE-2020-36237: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.
nvd
CVE-2017-18104P4MEDIUMCVSS 5.9fixed in 7.6.7≥ unspecified, < 7.6.7+2 more2018-07-24
CVE-2017-18104 [MEDIUM] CWE-200 CVE-2017-18104: The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.
nvd