cbcvebase.

Atlassian Jira vulnerabilities

155 known vulnerabilities affecting atlassian/jira.

Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3

Vulnerabilities

Page 6 of 8
CVE-2021-39121P4MEDIUMCVSS 4.3fixed in 8.5.182021-09-08
CVE-2021-39121 [MEDIUM] CVE-2021-39121: Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to e Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before version 8.5.18, from version 8.6.0 before 8.13.10, and from version 8.14.0 before 8.1
nvd
CVE-2008-6832P4MEDIUMCVSS 6.8v3.132009-06-08
CVE-2008-6832 [MEDIUM] CWE-352 CVE-2008-6832: Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows rem Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2019-14996P4MEDIUMCVSS 6.1≥ unspecified, < 7.13.7≥ 8.0.0, < unspecified+1 more2019-09-11
CVE-2019-14996 [MEDIUM] CWE-79 CVE-2019-14996: The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before ver The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
nvd
CVE-2017-16864P4MEDIUMCVSS 6.1fixed in 7.4.2vprior to 7.4.22018-01-12
CVE-2017-16864 [MEDIUM] CWE-79 CVE-2017-16864: The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject a The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.
nvd
CVE-2017-14594P4MEDIUMCVSS 6.1fixed in 7.2.12vprior 7.2.12+1 more2018-01-12
CVE-2017-14594 [MEDIUM] CWE-79 CVE-2017-14594: The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.
nvd
CVE-2018-5232P4MEDIUMCVSS 6.1fixed in 7.6.7≥ unspecified, < 7.6.7+2 more2018-07-18
CVE-2018-5232 [MEDIUM] CWE-79 CVE-2018-5232: The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before ver The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.
nvd
CVE-2017-18100P4MEDIUMCVSS 6.1fixed in 7.8.12018-04-10
CVE-2017-18100 [MEDIUM] CWE-79 CVE-2017-18100: The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.
nvd
CVE-2017-18098P4MEDIUMCVSS 6.1fixed in 7.6.1≥ unspecified, < 7.6.12018-04-06
CVE-2017-18098 [MEDIUM] CWE-79 CVE-2017-18098: The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inj The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields.
nvd
CVE-2020-14169P4MEDIUMCVSS 6.1fixed in 8.9.12020-07-01
CVE-2020-14169 [MEDIUM] CWE-79 CVE-2020-14169: The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attac The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability
nvd
CVE-2020-14164P4MEDIUMCVSS 6.1fixed in 8.8.22020-07-01
CVE-2020-14164 [MEDIUM] CWE-79 CVE-2020-14164: The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attack The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.
nvd
CVE-2019-20414P4MEDIUMCVSS 5.4fixed in 7.13.92020-06-29
CVE-2019-20414 [MEDIUM] CWE-79 CVE-2019-20414: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
nvd
CVE-2020-4021P4MEDIUMCVSS 5.4fixed in 7.13.162020-06-01
CVE-2020-4021 [MEDIUM] CWE-79 CVE-2020-4021: Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data C Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.
nvd
CVE-2020-4024P4MEDIUMCVSS 5.4fixed in 8.5.52020-07-01
CVE-2020-4024 [MEDIUM] CWE-79 CVE-2020-4024: The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6 The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a vnd.wap.xhtml+xml content type.
nvd
CVE-2018-20232P4MEDIUMCVSS 5.4fixed in 7.6.11≥ unspecified, < 7.6.11+2 more2019-02-13
CVE-2018-20232 [MEDIUM] CWE-79 CVE-2018-20232: The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before versi The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting.
nvd
CVE-2020-4029P4MEDIUMCVSS 4.3fixed in 8.5.52020-07-01
CVE-2020-4029 [MEDIUM] CVE-2020-4029: The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center befor The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability.
nvd
CVE-2019-15005P4MEDIUMCVSS 4.3fixed in 8.3.22019-11-08
CVE-2019-15005 [MEDIUM] CWE-862 CVE-2019-15005: The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivilege The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulne
nvd
CVE-2019-3400P4MEDIUMCVSS 6.1≥ unspecified, < 7.13.2≥ 8.0.0, < unspecified+1 more2019-05-03
CVE-2019-3400 [MEDIUM] CWE-79 CVE-2019-3400: The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter.
nvd
CVE-2019-11584P4MEDIUMCVSS 6.1fixed in 8.3.2≥ unspecified, < 8.3.22019-08-23
CVE-2019-11584 [MEDIUM] CWE-79 CVE-2019-11584: The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject ar The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.
nvd
CVE-2017-16863P4MEDIUMCVSS 6.1fixed in 7.5.32018-01-18
CVE-2017-16863 [MEDIUM] CWE-79 CVE-2017-16863: The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitra The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.
nvd
CVE-2019-8444P4MEDIUMCVSS 5.4≥ unspecified, < 7.13.6≥ 8.0.0, < unspecified+1 more2019-08-23
CVE-2019-8444 [MEDIUM] CWE-79 CVE-2019-8444: The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3. The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.
nvd
Atlassian Jira vulnerabilities | cvebase