Atlassian Jira vulnerabilities

155 known vulnerabilities affecting atlassian/jira.

Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3

Vulnerabilities

Page 6 of 8
CVE-2019-8448MEDIUMCVSS 5.3≥ unspecified, < 7.13.4≥ 8.0.0, < unspecified+1 more2019-08-13
CVE-2019-8448 [MEDIUM] CVE-2019-8448: The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 al The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
cvelistv5nvd
CVE-2018-20826MEDIUMCVSS 4.3fixed in 7.12.3≥ unspecified, < 7.12.32019-08-09
CVE-2018-20826 [MEDIUM] CWE-863 CVE-2018-20826: The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.
cvelistv5nvd
CVE-2018-20827MEDIUMCVSS 5.4≥ 7.0.0, < 7.13.1≥ unspecified, < 7.13.12019-08-09
CVE-2018-20827 [MEDIUM] CWE-79 CVE-2018-20827: The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter.
cvelistv5nvd
CVE-2019-11583MEDIUMCVSS 6.5fixed in 8.1.0≥ unspecified, < 8.1.02019-06-26
CVE-2019-11583 [MEDIUM] CVE-2019-11583: The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
cvelistv5nvd
CVE-2019-8442HIGHCVSS 7.5PoCfixed in 7.13.4≥ unspecified, < 7.13.4+4 more2019-05-22
CVE-2019-8442 [HIGH] CVE-2019-8442: The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 b The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
cvelistv5nvd
CVE-2019-8443HIGHCVSS 8.1fixed in 7.13.4≥ unspecified, < 7.13.4+4 more2019-05-22
CVE-2019-8443 [HIGH] CWE-287 CVE-2019-8443: The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, an The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access contro
cvelistv5nvd
CVE-2019-3403MEDIUMCVSS 5.3PoCfixed in 7.13.3≥ unspecified, < 7.13.3+4 more2019-05-22
CVE-2019-3403 [MEDIUM] CWE-863 CVE-2019-3403: The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before v The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
cvelistv5nvd
CVE-2019-3402MEDIUMCVSS 6.1PoCfixed in 7.13.3≥ unspecified, < 7.13.3+2 more2019-05-22
CVE-2019-3402 [MEDIUM] CWE-79 CVE-2019-3402: The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before v The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
cvelistv5nvd
CVE-2019-3401MEDIUMCVSS 5.3PoCfixed in 7.13.3≥ unspecified, < 7.13.3+2 more2019-05-22
CVE-2019-3401 [MEDIUM] CWE-863 CVE-2019-3401: The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
cvelistv5nvd
CVE-2018-20824MEDIUMCVSS 6.1PoCfixed in 7.13.1≥ unspecified, < 7.13.12019-05-03
CVE-2018-20824 [MEDIUM] CWE-79 CVE-2018-20824: The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitr The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
cvelistv5nvd
CVE-2019-3400MEDIUMCVSS 6.1≥ unspecified, < 7.13.2≥ 8.0.0, < unspecified+1 more2019-05-03
CVE-2019-3400 [MEDIUM] CWE-79 CVE-2019-3400: The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter.
cvelistv5nvd
CVE-2019-3399HIGHCVSS 7.5fixed in 7.13.2≥ unspecified, < 7.13.2+2 more2019-04-30
CVE-2019-3399 [HIGH] CWE-863 CVE-2019-3399: The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before versio The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.
cvelistv5nvd
CVE-2018-13404MEDIUMCVSS 4.1fixed in 7.6.10≥ unspecified, < 7.6.10+14 more2019-02-13
CVE-2018-13404 [MEDIUM] CWE-918 CVE-2018-13404: The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 b The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.
cvelistv5nvd
CVE-2018-20232MEDIUMCVSS 5.4fixed in 7.6.11≥ unspecified, < 7.6.11+2 more2019-02-13
CVE-2018-20232 [MEDIUM] CWE-79 CVE-2018-20232: The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before versi The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting.
cvelistv5nvd
CVE-2018-13403MEDIUMCVSS 5.4fixed in 7.6.10≥ unspecified, < 7.6.10+4 more2019-02-13
CVE-2018-13403 [MEDIUM] CWE-79 CVE-2018-13403: The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7 The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.
cvelistv5nvd
CVE-2018-13402MEDIUMCVSS 6.1fixed in 7.6.9≥ unspecified, < 7.6.9+14 more2018-10-23
CVE-2018-13402 [MEDIUM] CWE-601 CVE-2018-13402: Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allow remote attac
cvelistv5nvd
CVE-2018-13400MEDIUMCVSS 4.7fixed in 7.6.9≥ unspecified, < 7.6.9+14 more2018-10-23
CVE-2018-13400 [MEDIUM] CWE-269 CVE-2018-13400: Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before v Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1
cvelistv5nvd
CVE-2018-13401MEDIUMCVSS 6.1fixed in 7.6.9≥ unspecified, < 7.6.9+14 more2018-10-23
CVE-2018-13401 [MEDIUM] CWE-601 CVE-2018-13401: The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before versi The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allo
cvelistv5nvd
CVE-2018-13391MEDIUMCVSS 5.3fixed in 7.6.8≥ unspecified, < 7.6.8+10 more2018-08-28
CVE-2018-13391 [MEDIUM] CWE-200 CVE-2018-13391: The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before v The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain th
cvelistv5nvd
CVE-2018-13395MEDIUMCVSS 6.1fixed in 7.6.8≥ unspecified, < 7.6.8+10 more2018-08-28
CVE-2018-13395 [MEDIUM] CWE-79 CVE-2018-13395: Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, f Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerab
cvelistv5nvd