Atlassian Jira vulnerabilities
155 known vulnerabilities affecting atlassian/jira.
Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3
Vulnerabilities
Page 7 of 8
CVE-2017-18104MEDIUMCVSS 5.9fixed in 7.6.7≥ unspecified, < 7.6.7+2 more2018-07-24
CVE-2017-18104 [MEDIUM] CWE-200 CVE-2017-18104: The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.
cvelistv5nvd
CVE-2018-5232MEDIUMCVSS 6.1fixed in 7.6.7≥ unspecified, < 7.6.7+2 more2018-07-18
CVE-2018-5232 [MEDIUM] CWE-79 CVE-2018-5232: The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before ver
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.
cvelistv5nvd
CVE-2018-13387MEDIUMCVSS 6.1fixed in 7.6.72018-07-16
CVE-2018-13387 [MEDIUM] CVE-2018-13387: The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 b
The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7.10.0 before version 7.10.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability i
cvelistv5nvd
CVE-2018-5231HIGHCVSS 7.5fixed in 7.6.6≥ unspecified, < 7.6.6+6 more2018-05-16
CVE-2018-5231 [HIGH] CVE-2018-5231: The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before ve
The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to perform a denial of service attack via sending requests to it.
cvelistv5nvd
CVE-2018-5230MEDIUMCVSS 6.1PoCfixed in 7.6.6≥ unspecified, < 7.6.6+6 more2018-05-14
CVE-2018-5230 [MEDIUM] CWE-79 CVE-2018-5230: The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4,
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value
cvelistv5nvd
CVE-2017-18101MEDIUMCVSS 6.5fixed in 7.6.5≥ unspecified, < 7.6.5+4 more2018-04-10
CVE-2017-18101 [MEDIUM] CWE-284 CVE-2017-18101: Various administrative external system import resources in Atlassian JIRA Server (including JIRA Cor
Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow remote attackers to run import operations and to determine if an internal service exists through missing permissio
cvelistv5nvd
CVE-2017-18100MEDIUMCVSS 6.1fixed in 7.8.12018-04-10
CVE-2017-18100 [MEDIUM] CWE-79 CVE-2017-18100: The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject
The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.
nvd
CVE-2017-18097MEDIUMCVSS 5.4fixed in 7.6.1≥ unspecified, < 7.6.12018-04-06
CVE-2017-18097 [MEDIUM] CWE-79 CVE-2017-18097: The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers wh
The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.
cvelistv5nvd
CVE-2017-18098MEDIUMCVSS 6.1fixed in 7.6.1≥ unspecified, < 7.6.12018-04-06
CVE-2017-18098 [MEDIUM] CWE-79 CVE-2017-18098: The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inj
The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields.
cvelistv5nvd
CVE-2017-18039MEDIUMCVSS 6.1≥ 6.2.1, < 7.4.4≥ unspecified, < 7.6.7+8 more2018-02-02
CVE-2017-18039 [MEDIUM] CWE-79 CVE-2017-18039: The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows re
The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter.
cvelistv5nvd
CVE-2017-18033MEDIUMCVSS 6.5fixed in 7.6.1vAll versions before 7.6.12018-01-18
CVE-2017-18033 [MEDIUM] CWE-352 CVE-2017-18033: The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create n
The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.
cvelistv5nvd
CVE-2017-16863MEDIUMCVSS 6.1fixed in 7.5.32018-01-18
CVE-2017-16863 [MEDIUM] CWE-79 CVE-2017-16863: The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitra
The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.
nvd
CVE-2017-16865MEDIUMCVSS 5.3fixed in 7.6.1vAll versions before 7.6.12018-01-17
CVE-2017-16865 [MEDIUM] CWE-918 CVE-2017-16865: The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the con
The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential info
cvelistv5nvd
CVE-2017-16862MEDIUMCVSS 4.3fixed in 7.6.2vprior to 7.6.22018-01-12
CVE-2017-16862 [MEDIUM] CWE-352 CVE-2017-16862: The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to m
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.
cvelistv5nvd
CVE-2017-14594MEDIUMCVSS 6.1fixed in 7.2.12vprior 7.2.12+1 more2018-01-12
CVE-2017-14594 [MEDIUM] CWE-79 CVE-2017-14594: The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.
cvelistv5nvd
CVE-2017-16864MEDIUMCVSS 6.1fixed in 7.4.2vprior to 7.4.22018-01-12
CVE-2017-16864 [MEDIUM] CWE-79 CVE-2017-16864: The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject a
The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.
cvelistv5nvd
CVE-2017-5983CRITICALCVSS 9.8PoCv4.2.4v4.3+64 more2017-04-10
CVE-2017-5983 [CRITICAL] CWE-502 CVE-2017-5983: The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parse
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
nvd
CVE-2016-4319HIGHCVSS 8.8≤ 7.1.82017-04-10
CVE-2016-4319 [HIGH] CWE-352 CVE-2016-4319: Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
nvd
CVE-2016-4318MEDIUMCVSS 4.8≤ 7.1.82017-04-10
CVE-2016-4318 [MEDIUM] CWE-79 CVE-2016-4318: Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role n
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
nvd
CVE-2016-6285MEDIUMCVSS 6.1≤ 7.2.12017-01-31
CVE-2016-6285 [MEDIUM] CWE-79 CVE-2016-6285: Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian
Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
nvd