cbcvebase.

Atlassian Jira vulnerabilities

155 known vulnerabilities affecting atlassian/jira.

Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3

Vulnerabilities

Page 4 of 8
CVE-2017-16865P4MEDIUMCVSS 5.3fixed in 7.6.1vAll versions before 7.6.12018-01-17
CVE-2017-16865 [MEDIUM] CWE-918 CVE-2017-16865: The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the con The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential info
nvd
CVE-2019-8445P4MEDIUMCVSS 5.3≥ unspecified, < 7.13.7≥ 8.0.0, < unspecified+1 more2019-08-23
CVE-2019-8445 [MEDIUM] CWE-863 CVE-2019-8445: Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
nvd
CVE-2019-20412P4MEDIUMCVSS 5.3fixed in 7.13.92020-06-29
CVE-2019-20412 [MEDIUM] CWE-287 CVE-2019-20412: The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center all The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue Keys; Issue Types; Status Types. The affected versions are before version 7
nvd
CVE-2021-39122P4MEDIUMCVSS 5.3fixed in 8.5.132021-09-08
CVE-2021-39122 [MEDIUM] CVE-2021-39122: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
nvd
CVE-2008-6531P4MEDIUMCVSS 6.8fixed in 3.13.22009-03-26
CVE-2008-6531 [MEDIUM] CWE-94 CVE-2008-6531: The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to i The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted URL that is dynamically transformed into method calls, aka "WebWork 1 Parameter Injection Hole."
nvd
CVE-2014-2313P4MEDIUMCVSS 4.3≤ 6.0.4v6.0+3 more2014-03-09
CVE-2014-2313 [MEDIUM] CWE-22 CVE-2014-2313: Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remo Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.
nvd
CVE-2019-14998P4MEDIUMCVSS 6.5≥ unspecified, < 8.4.02019-09-11
CVE-2019-14998 [MEDIUM] CWE-352 CVE-2019-14998: The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before versio The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.
nvd
CVE-2019-8448P4MEDIUMCVSS 5.3≥ unspecified, < 7.13.4≥ 8.0.0, < unspecified+1 more2019-08-13
CVE-2019-8448 [MEDIUM] CVE-2019-8448: The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 al The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
nvd
CVE-2020-36286P4MEDIUMCVSS 5.3fixed in 8.5.132021-04-01
CVE-2020-36286 [MEDIUM] CVE-2020-36286: The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field.
nvd
CVE-2021-39119P4MEDIUMCVSS 5.3fixed in 8.19.02021-09-01
CVE-2021-39119 [MEDIUM] CWE-863 CVE-2021-39119: Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected versions are before version 8.19.0.
nvd
CVE-2019-11583P4MEDIUMCVSS 6.5fixed in 8.1.0≥ unspecified, < 8.1.02019-06-26
CVE-2019-11583 [MEDIUM] CVE-2019-11583: The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
nvd
CVE-2019-11587P4MEDIUMCVSS 6.5fixed in 7.13.6≥ unspecified, < 7.13.6+4 more2019-08-23
CVE-2019-11587 [MEDIUM] CWE-352 CVE-2019-11587: Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).
nvd
CVE-2018-13401P4MEDIUMCVSS 6.1fixed in 7.6.9≥ unspecified, < 7.6.9+14 more2018-10-23
CVE-2018-13401 [MEDIUM] CWE-601 CVE-2018-13401: The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before versi The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allo
nvd
CVE-2020-14165P4MEDIUMCVSS 5.3fixed in 8.9.02020-07-01
CVE-2020-14165 [MEDIUM] CVE-2020-14165: The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.
nvd
CVE-2019-20408P4MEDIUMCVSS 5.3fixed in 8.7.02020-07-01
CVE-2019-20408 [MEDIUM] CWE-918 CVE-2019-20408: The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attacke The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
nvd
CVE-2018-13400P4MEDIUMCVSS 4.7fixed in 7.6.9≥ unspecified, < 7.6.9+14 more2018-10-23
CVE-2018-13400 [MEDIUM] CWE-269 CVE-2018-13400: Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before v Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1
nvd
CVE-2017-18033P4MEDIUMCVSS 6.5fixed in 7.6.1vAll versions before 7.6.12018-01-18
CVE-2017-18033 [MEDIUM] CWE-352 CVE-2017-18033: The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create n The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.
nvd
CVE-2020-36288P4MEDIUMCVSS 6.1fixed in 8.5.122021-04-15
CVE-2020-36288 [MEDIUM] CWE-79 CVE-2020-36288: The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from vers The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused by parameter pollution.
nvd
CVE-2018-13402P4MEDIUMCVSS 6.1fixed in 7.6.9≥ unspecified, < 7.6.9+14 more2018-10-23
CVE-2018-13402 [MEDIUM] CWE-601 CVE-2018-13402: Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allow remote attac
nvd
CVE-2020-36236P4MEDIUMCVSS 6.1fixed in 8.5.112021-02-15
CVE-2020-36236 [MEDIUM] CWE-79 CVE-2020-36236: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15
nvd
Atlassian Jira vulnerabilities | cvebase