cbcvebase.

Atlassian Jira vulnerabilities

155 known vulnerabilities affecting atlassian/jira.

Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3

Vulnerabilities

Page 7 of 8
CVE-2017-18097P4MEDIUMCVSS 5.4fixed in 7.6.1≥ unspecified, < 7.6.12018-04-06
CVE-2017-18097 [MEDIUM] CWE-79 CVE-2017-18097: The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers wh The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.
nvd
CVE-2019-20100P4MEDIUMCVSS 4.7≥ 7.0.0, < 8.4.52020-02-12
CVE-2019-20100 [MEDIUM] CWE-352 CVE-2019-20100: The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The follo The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.2, and from version 7.1.0 before version 7.1.3. The vulnerable plugin is
nvd
CVE-2019-15013P4MEDIUMCVSS 4.3fixed in 7.13.12≥ unspecified, < 7.13.12+4 more2019-12-18
CVE-2019-15013 [MEDIUM] CWE-862 CVE-2019-15013: The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 be The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.
nvd
CVE-2020-29451P4MEDIUMCVSS 4.3fixed in 8.5.112021-02-15
CVE-2020-29451 [MEDIUM] CVE-2020-29451: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.
nvd
CVE-2017-18039P4MEDIUMCVSS 6.1≥ 6.2.1, < 7.4.4≥ unspecified, < 7.6.7+8 more2018-02-02
CVE-2017-18039 [MEDIUM] CWE-79 CVE-2017-18039: The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows re The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter.
nvd
CVE-2018-20827P4MEDIUMCVSS 5.4≥ 7.0.0, < 7.13.1≥ unspecified, < 7.13.12019-08-09
CVE-2018-20827 [MEDIUM] CWE-79 CVE-2018-20827: The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter.
nvd
CVE-2007-6618P4MEDIUMCVSS 5.0≤ 3.122008-01-03
CVE-2007-6618 [MEDIUM] CVE-2007-6618: JIRA Enterprise Edition before 3.12.1 allows remote attackers to delete another user's shared filter JIRA Enterprise Edition before 3.12.1 allows remote attackers to delete another user's shared filter via a modified filter ID.
nvd
CVE-2021-39112P4MEDIUMCVSS 4.8fixed in 8.5.152021-08-25
CVE-2021-39112 [MEDIUM] CWE-1022 CVE-2021-39112: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from version 8.14.0 before 8.17.1, and from version 8.18.0 before 8.18.1.
nvd
CVE-2018-20826P4MEDIUMCVSS 4.3fixed in 7.12.3≥ unspecified, < 7.12.32019-08-09
CVE-2018-20826 [MEDIUM] CWE-863 CVE-2018-20826: The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.
nvd
CVE-2018-13404P4MEDIUMCVSS 4.1fixed in 7.6.10≥ unspecified, < 7.6.10+14 more2019-02-13
CVE-2018-13404 [MEDIUM] CWE-918 CVE-2018-13404: The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 b The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.
nvd
CVE-2021-26075P4MEDIUMCVSS 4.3fixed in 8.5.122021-04-15
CVE-2021-26075 [MEDIUM] CVE-2021-26075: The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before ve The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data directory via an information disclosure vulnerability in the error message when p
nvd
CVE-2020-14183P4MEDIUMCVSS 4.3fixed in 7.13.18≥ 8.0.0, < 8.5.9+1 more2020-10-06
CVE-2020-14183 [MEDIUM] CWE-200 CVE-2020-14183: Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) priv Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 befor
nvd
CVE-2020-36234P4MEDIUMCVSS 4.8fixed in 8.5.112021-02-15
CVE-2020-36234 [MEDIUM] CWE-79 CVE-2020-36234: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
nvd
CVE-2020-4025P4MEDIUMCVSS 4.8fixed in 8.5.52020-07-01
CVE-2020-4025 [MEDIUM] CWE-79 CVE-2020-4025: The attachment download resource in Atlassian Jira Server and Data Center The attachment download re The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a
nvd
CVE-2016-4318P4MEDIUMCVSS 4.8≤ 7.1.82017-04-10
CVE-2016-4318 [MEDIUM] CWE-79 CVE-2016-4318: Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role n Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
nvd
CVE-2021-39117P4MEDIUMCVSS 4.8fixed in 8.18.02021-08-30
CVE-2021-39117 [MEDIUM] CWE-79 CVE-2021-39117: The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allo The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field.
nvd
CVE-2021-43945P4MEDIUMCVSS 4.8fixed in 8.20.32022-02-28
CVE-2021-43945 [MEDIUM] CWE-79 CVE-2021-43945: Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Admi Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
nvd
CVE-2019-14997P4MEDIUMCVSS 4.3≥ unspecified, < 8.4.02019-09-11
CVE-2019-14997 [MEDIUM] CWE-524 CVE-2019-14997: The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn de The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.
nvd
CVE-2021-39124P4MEDIUMCVSS 4.3fixed in 8.16.02021-09-14
CVE-2021-39124 [MEDIUM] CWE-352 CVE-2021-39124: The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.
nvd
CVE-2021-43953P4MEDIUMCVSS 4.3fixed in 8.13.16≥ 8.14.0, < 8.20.52022-02-15
CVE-2021-43953 [MEDIUM] CWE-352 CVE-2021-43953: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.
nvd
Atlassian Jira vulnerabilities | cvebase