cbcvebase.

Atlassian Jira vulnerabilities

155 known vulnerabilities affecting atlassian/jira.

Total CVEs
155
CISA KEV
0
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL5HIGH19MEDIUM128LOW3

Vulnerabilities

Page 8 of 8
CVE-2013-5319P4MEDIUMCVSS 4.3≤ 6.0.4v6.0+3 more2013-08-20
CVE-2013-5319 [MEDIUM] CWE-79 CVE-2013-5319: Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Adm Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in Atlassian JIRA before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via the name parameter to secure/admin/user/DeleteUser!default.jspa.
nvd
CVE-2019-8450P4MEDIUMCVSS 4.8≥ unspecified, < 7.13.6≥ 8.0.0, < unspecified+1 more2019-09-11
CVE-2019-8450 [MEDIUM] CWE-79 CVE-2019-8450: Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 b Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a custom field.
nvd
CVE-2019-20416P4MEDIUMCVSS 4.8fixed in 8.3.02020-06-30
CVE-2019-20416 [MEDIUM] CWE-79 CVE-2019-20416: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.
nvd
CVE-2019-20411P4MEDIUMCVSS 4.3fixed in 7.13.92020-06-29
CVE-2019-20411 [MEDIUM] CWE-352 CVE-2019-20411: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
nvd
CVE-2019-20415P4MEDIUMCVSS 4.3fixed in 7.13.32020-06-30
CVE-2019-20415 [MEDIUM] CWE-352 CVE-2019-20415: Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.3, and from version 8.0.0 before 8.1.0.
nvd
CVE-2008-6831P4MEDIUMCVSS 4.3v3.132009-06-08
CVE-2008-6831 [MEDIUM] CWE-79 CVE-2008-6831: Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname (Full Name) parameter in the ViewProfile page or (2) returnUrl parameter in a form, as demonstrated using secure/AddComment!default.jspa (aka "Add Comment").
nvd
CVE-2019-8447P4MEDIUMCVSS 4.3≥ unspecified, < 8.3.22019-08-23
CVE-2019-8447 [MEDIUM] CWE-352 CVE-2019-8447: The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the cre The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2019-11586P4MEDIUMCVSS 4.3fixed in 7.13.6≥ unspecified, < 7.13.6+4 more2019-08-23
CVE-2019-11586 [MEDIUM] CWE-352 CVE-2019-11586: The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2 The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2021-26076P4LOWCVSS 3.7fixed in 8.5.122021-04-15
CVE-2021-26076 [LOW] CVE-2021-26076: The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote anonymous attackers who can perform an attacker in the middle attack to learn which mode a user is editing in due to the cookie not being set w
nvd
CVE-2019-11588P4MEDIUMCVSS 4.3fixed in 7.13.6≥ unspecified, < 7.13.6+4 more2019-08-23
CVE-2019-11588 [MEDIUM] CWE-352 CVE-2019-11588: The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0. The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2007-6617P4MEDIUMCVSS 4.3≤ 3.122008-01-03
CVE-2007-6617 [MEDIUM] CWE-79 CVE-2007-6617: Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 all Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 allows remote attackers to inject arbitrary web script or HTML, which is not properly handled when generating error messages, as demonstrated by input originally sent in the URI to secure/CreateIssue. NOTE: some of these details are obtained from third part
nvd
CVE-2017-16862P4MEDIUMCVSS 4.3fixed in 7.6.2vprior to 7.6.22018-01-12
CVE-2017-16862 [MEDIUM] CWE-352 CVE-2017-16862: The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to m The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2021-26071P4LOWCVSS 3.5fixed in 8.5.132021-04-01
CVE-2021-26071 [LOW] CWE-352 CVE-2021-26071: The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from versi The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2006-3338P4LOWCVSS 2.6v3.6.2_1562006-07-03
CVE-2006-3338 [LOW] CVE-2006-3338: Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inj Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a direct request to secure/ConfigureReleaseNote.jspa, which are not sanitized before being returned in an error page.
nvd
CVE-2006-3339P4MEDIUMCVSS 5.0v3.6.2_1562006-07-03
CVE-2006-3339 [MEDIUM] CVE-2006-3339: secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-#156 allows remote attackers to obtain sens secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-#156 allows remote attackers to obtain sensitive information via unspecified manipulations of the projectId parameter, which displays the installation path and other system information in an error message.
nvd
Atlassian Jira vulnerabilities | cvebase