cbcvebase.

Atlassian Jira vulnerabilities

155 known vulnerabilities affecting atlassian/jira.

Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3

Vulnerabilities

Page 5 of 8
CVE-2021-39111P4MEDIUMCVSS 6.1fixed in 8.5.182021-08-30
CVE-2021-39111 [MEDIUM] CWE-79 CVE-2021-39111: The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into a field such as the desc
nvd
CVE-2016-6285P4MEDIUMCVSS 6.1≤ 7.2.12017-01-31
CVE-2016-6285 [MEDIUM] CWE-79 CVE-2016-6285: Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
nvd
CVE-2018-13387P4MEDIUMCVSS 6.1fixed in 7.6.72018-07-16
CVE-2018-13387 [MEDIUM] CVE-2018-13387: The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 b The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7.10.0 before version 7.10.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability i
nvd
CVE-2021-26079P4MEDIUMCVSS 6.1fixed in 8.5.152021-06-07
CVE-2021-26079 [MEDIUM] CWE-79 CVE-2021-26079: The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and f The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
nvd
CVE-2020-14173P4MEDIUMCVSS 5.4fixed in 8.5.42020-07-03
CVE-2020-14173 [MEDIUM] CWE-79 CVE-2020-14173: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2021-26082P4MEDIUMCVSS 5.4fixed in 8.5.142021-07-20
CVE-2021-26082 [MEDIUM] CWE-79 CVE-2021-26082: The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6 The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a stored cross site scripting vulnerability.
nvd
CVE-2020-4028P4MEDIUMCVSS 5.3fixed in 8.9.12020-06-23
CVE-2020-4028 [MEDIUM] CWE-203 CVE-2020-4028: Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthe Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.
nvd
CVE-2020-36231P4MEDIUMCVSS 4.3fixed in 8.5.102021-02-02
CVE-2020-36231 [MEDIUM] CWE-639 CVE-2020-36231: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metada Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
nvd
CVE-2019-20106P4MEDIUMCVSS 4.3fixed in 7.13.122020-02-06
CVE-2019-20106 [MEDIUM] CWE-276 CVE-2019-20106: Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 befor Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
nvd
CVE-2019-11585P4MEDIUMCVSS 6.1fixed in 7.13.6≥ unspecified, < 7.13.6+4 more2019-08-23
CVE-2019-11585 [MEDIUM] CWE-601 CVE-2019-11585: The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
nvd
CVE-2019-20901P4MEDIUMCVSS 6.1fixed in 8.5.22020-07-13
CVE-2019-20901 [MEDIUM] CWE-601 CVE-2019-20901: The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 all The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter.
nvd
CVE-2020-4022P4MEDIUMCVSS 6.1fixed in 8.5.52020-07-01
CVE-2020-4022 [MEDIUM] CWE-79 CVE-2020-4022: The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6 The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a mixed multipart content type.
nvd
CVE-2019-11589P4MEDIUMCVSS 6.1≥ unspecified, < 7.13.6≥ 8.0.0, < unspecified+3 more2019-08-23
CVE-2019-11589 [MEDIUM] CWE-601 CVE-2019-11589: The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before versio The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.
nvd
CVE-2018-13395P4MEDIUMCVSS 6.1fixed in 7.6.8≥ unspecified, < 7.6.8+10 more2018-08-28
CVE-2018-13395 [MEDIUM] CWE-79 CVE-2018-13395: Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, f Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerab
nvd
CVE-2021-41304P4MEDIUMCVSS 6.1fixed in 8.13.122021-10-26
CVE-2021-41304 [MEDIUM] CWE-79 CVE-2021-41304: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to injec Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.2.
nvd
CVE-2020-14184P4MEDIUMCVSS 5.4fixed in 8.5.92020-10-12
CVE-2020-14184 [MEDIUM] CWE-79 CVE-2020-14184: Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaSc Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected versions are before 8.5.9, from version 8.6.0 before 8.12.3, and from version 8.13.0 before 8.13.1.
nvd
CVE-2018-13403P4MEDIUMCVSS 5.4fixed in 7.6.10≥ unspecified, < 7.6.10+4 more2019-02-13
CVE-2018-13403 [MEDIUM] CWE-79 CVE-2018-13403: The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7 The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.
nvd
CVE-2021-26083P4MEDIUMCVSS 5.4fixed in 8.5.142021-07-20
CVE-2021-26083 [MEDIUM] CWE-79 CVE-2021-26083: Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2019-20402P4MEDIUMCVSS 4.9fixed in 8.6.02020-02-06
CVE-2019-20402 [MEDIUM] CVE-2019-20402: Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
nvd
CVE-2020-14174P4MEDIUMCVSS 4.3fixed in 7.13.162020-07-13
CVE-2020-14174 [MEDIUM] CWE-639 CVE-2020-14174: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version
nvd
Atlassian Jira vulnerabilities | cvebase