cbcvebase.

Atlassian Jira Data Center vulnerabilities

102 known vulnerabilities affecting atlassian/jira_data_center.

Total CVEs
102
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH21MEDIUM76LOW2

Vulnerabilities

Page 1 of 6
CVE-2021-26086P1MEDIUMCVSS 5.3KEVPoCfixed in 8.5.14≥ 8.6.0, < 8.13.6+6 more2021-08-16
CVE-2021-26086 [MEDIUM] CWE-22 CVE-2021-26086: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
nvd
CVE-2022-0540P1CRITICALCVSS 9.8ExploitedPoCfixed in 8.13.8≥ 8.14.0, < 8.20.6+1 more2022-04-20
CVE-2022-0540 [CRITICAL] CWE-287 CVE-2022-0540: A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Manag
nvd
CVE-2024-21683P1HIGHCVSS 8.8ExploitedPoC≥ 9.4.0, < 9.4.21≥ 9.12.0, < 9.12.82024-05-21
CVE-2024-21683 [HIGH] CWE-94 CVE-2024-21683: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Conflu This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availabi
nvd
CVE-2020-36289P2MEDIUMCVSS 5.3PoC≥ 8.6.0, < 8.13.5≥ 8.14.0, < 8.15.1+5 more2021-05-12
CVE-2020-36289 [MEDIUM] CWE-863 CVE-2020-36289: Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerat Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
nvd
CVE-2020-14179P2MEDIUMCVSS 5.3PoCfixed in 8.5.8≥ 8.6.0, < 8.11.12020-09-21
CVE-2020-14179 [MEDIUM] CVE-2020-14179: Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers t Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.
nvd
CVE-2020-36239P2CRITICALCVSS 9.8≥ 6.3.0, < 8.5.16≥ 8.6.0, < 8.13.8+7 more2021-07-29
CVE-2020-36239 [CRITICAL] CWE-862 CVE-2020-36239: Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attack
nvd
CVE-2020-29453P3MEDIUMCVSS 5.3PoC≥ 8.14.0, < 8.15.0≥ unspecified, < 8.5.11+4 more2021-02-22
CVE-2020-29453 [MEDIUM] CWE-22 CVE-2020-29453: The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5. The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
nvd
CVE-2022-26135P3MEDIUMCVSS 6.5≥ 8.0.0, < 8.13.22≥ 8.14.0, < 8.20.10+1 more2022-06-30
CVE-2022-26135 [MEDIUM] CWE-918 CVE-2022-26135: A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.
nvd
CVE-2022-36799P2HIGHCVSS 7.2fixed in 8.13.19≥ 8.14.0, < 8.20.7+6 more2022-08-01
CVE-2022-36799 [HIGH] CWE-94 CVE-2022-36799: This issue exists to document that a security improvement in the way that Jira Server and Data Cente This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the
nvd
CVE-2022-26136P2CRITICALCVSS 9.8≥ 8.13.0, < 8.13.22≥ 8.14.0, < 8.20.10+1 more2022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
nvd
CVE-2021-26078P3MEDIUMCVSS 6.1PoC≥ unspecified, < 8.5.14≥ 8.6.0, < unspecified+3 more2021-06-07
CVE-2021-26078 [MEDIUM] CWE-79 CVE-2021-26078: The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
nvd
CVE-2019-15001P3HIGHCVSS 7.2≥ 7.0.10, < 7.6.16≥ 7.7.0, < 7.13.8+16 more2019-09-19
CVE-2019-15001 [HIGH] CWE-94 CVE-2019-15001: The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7. The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerabil
nvd
CVE-2025-22157P3HIGHCVSS 8.8≥ 5.12.0, < 5.12.20≥ 9.12.0, < 9.12.20+2 more2025-05-20
CVE-2025-22157 [HIGH] CWE-284 CVE-2025-22157: This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perf
nvd
CVE-2022-26137P3HIGHCVSS 8.8≥ 8.13.0, < 8.13.22≥ 8.14.0, < 8.20.10+1 more2022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
nvd
CVE-2017-18113P3HIGHCVSS 8.8≥ unspecified, < 8.18.12021-08-02
CVE-2017-18113 [HIGH] CWE-94 CVE-2017-18113: The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 al The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code Execution (RCE) vulnerability. The vulnerability allowed for various problematic OSWorkflow classes to be used as pa
nvd
CVE-2022-36801P3MEDIUMCVSS 6.1fixed in 8.20.8≥ unspecified, < 8.20.82022-08-10
CVE-2022-36801 [MEDIUM] CWE-79 CVE-2022-36801: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to injec Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8.
nvd
CVE-2021-43942P3MEDIUMCVSS 6.1≥ unspecified, < 8.13.15≥ 8.14.0, < unspecified+1 more2022-01-04
CVE-2021-43942 [MEDIUM] CWE-79 CVE-2021-43942: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. To exploit this issue, the attacker must trick a user into visiting a malicious website. The affected versions are befor
nvd
CVE-2021-43947P3HIGHCVSS 7.2≥ 8.14.0, < 8.20.3≥ unspecified, < 8.13.15+2 more2022-01-06
CVE-2021-43947 [HIGH] CVE-2021-43947: Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected versions are before version 8.13.15, and from ver
nvd
CVE-2021-43944P3HIGHCVSS 7.2fixed in 8.13.15≥ 8.14.0, < 8.20.3+3 more2022-03-08
CVE-2021-43944 [HIGH] CWE-94 CVE-2021-43944: This issue exists to document that a security improvement in the way that Jira Server and Data Cente This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the
nvd
CVE-2021-39128P3HIGHCVSS 7.2fixed in 8.13.12≥ 8.14.0, < 8.19.1+3 more2021-09-16
CVE-2021-39128 [HIGH] CWE-1336 CVE-2021-39128: Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon al Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-side template injection vulnerability in the Email Template feature. The affected versions of Jira Server or Data Center are before version 8.13.12, and fr
nvd
Atlassian Jira Data Center vulnerabilities | cvebase