Atlassian Jira Data Center vulnerabilities
102 known vulnerabilities affecting atlassian/jira_data_center.
Total CVEs
102
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH21MEDIUM76LOW2
Vulnerabilities
Page 2 of 6
CVE-2021-41307P3HIGHCVSS 7.5≥ unspecified, < 8.13.12≥ 8.14.0, < unspecified+1 more2021-10-26
CVE-2021-41307 [HIGH] CWE-639 CVE-2021-41307: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie Chart Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0.
nvd
CVE-2021-39113P3HIGHCVSS 7.5≥ 8.14.0, < 8.18.0≥ unspecified, < 8.13.9+2 more2021-08-30
CVE-2021-39113 [HIGH] CWE-613 CVE-2021-39113: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to conti
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0.
nvd
CVE-2021-41312P3HIGHCVSS 7.5≥ unspecified, < 8.19.12021-11-03
CVE-2021-41312 [HIGH] CWE-287 CVE-2021-41312: Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.
nvd
CVE-2020-14178P3HIGHCVSS 7.5≥ 8.0.0, < 8.5.8≥ 8.6.0, < 8.12.02020-09-01
CVE-2020-14178 [HIGH] CVE-2020-14178: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate proje
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.
nvd
CVE-2021-41306P3HIGHCVSS 7.5≥ unspecified, < 8.13.12≥ 8.14.0, < unspecified+1 more2021-10-26
CVE-2021-41306 [HIGH] CWE-639 CVE-2021-41306: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0.
nvd
CVE-2021-26070P3HIGHCVSS 7.2≥ unspecified, < 8.13.3≥ 8.14.0, < unspecified+1 more2021-03-22
CVE-2021-26070 [HIGH] CWE-287 CVE-2021-26070: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-th
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
nvd
CVE-2021-41311P3HIGHCVSS 7.5≥ unspecified, < 8.19.12021-12-08
CVE-2021-41311 [HIGH] CWE-287 CVE-2021-41311: Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an adminis
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.
nvd
CVE-2025-22167P3MEDIUMCVSS 6.5≥ 9.12.0, < 9.12.28≥ 10.3.0, < 10.3.12+1 more2025-10-22
CVE-2025-22167 [MEDIUM] CWE-22 CVE-2025-22167: This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0
This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by the Jira JVM process. Atlassian r
nvd
CVE-2021-39123P3HIGHCVSS 7.5≥ unspecified, < 8.16.02021-09-14
CVE-2021-39123 [HIGH] CVE-2021-39123: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint. The affected versions are before version 8.16.0.
nvd
CVE-2021-41305P3HIGHCVSS 7.5≥ unspecified, < 8.13.122021-10-26
CVE-2021-41305 [HIGH] CWE-639 CVE-2021-41305: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in Status Gadget. The affected versions are before version 8.13.12..
nvd
CVE-2019-20413P3HIGHCVSS 7.5≥ 8.0.0, < 8.4.22020-06-29
CVE-2019-20413 [HIGH] CVE-2019-20413: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the appl
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPickerBrowser.jspa page. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
nvd
CVE-2019-20419P3HIGHCVSS 7.8fixed in 8.5.5≥ 8.6.0, < 8.7.22020-07-03
CVE-2019-20419 [HIGH] CWE-427 CVE-2019-20419: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitra
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8.6.0 before 8.7.2.
nvd
CVE-2021-43946P3MEDIUMCVSS 6.5fixed in 8.13.21≥ 8.14.0, < 8.20.9+3 more2022-01-05
CVE-2021-43946 [MEDIUM] CVE-2021-43946: Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to a
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.13.21, and from version 8.14.0 before 8.20.9.
nvd
CVE-2021-41308P3MEDIUMCVSS 6.5≥ 8.7.0, < 8.13.12≥ unspecified, < 8.6.0+4 more2021-10-26
CVE-2021-41308 [MEDIUM] CWE-285 CVE-2021-41308: Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the `ReplicationSettings!default.jspa` endpoint. The affected versions are before version 8.6.0, from version 8.7.0 before 8.13.12, and from version 8
nvd
CVE-2020-14167P3HIGHCVSS 7.5≥ 8.5.0, < 8.5.5≥ 8.8.0, < 8.8.2+1 more2020-07-01
CVE-2020-14167 [HIGH] CVE-2020-14167: The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0
The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the application's availability via an Denial of Service (DoS) vulnerability.
nvd
CVE-2020-36287P3MEDIUMCVSS 5.3≥ 8.14.0, < 8.15.1≥ unspecified, < 8.13.5+2 more2021-04-09
CVE-2020-36287 [MEDIUM] CWE-863 CVE-2020-36287: The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Ji
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.
nvd
CVE-2019-20410P3MEDIUMCVSS 6.5≥ 7.7.0, < 7.13.9≥ 8.0.0, < 8.4.22020-06-29
CVE-2019-20410 [MEDIUM] CVE-2019-20410: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the comment restriction feature. The affected versions are before version 7.6.17, from version 7.7.0 before 7.13.9, and from version 8.0.0 before 8.4.2.
nvd
CVE-2020-14168P3MEDIUMCVSS 5.9≥ 8.5.0, < 8.5.5≥ 8.8.0, < 8.8.2+1 more2020-07-01
CVE-2020-14168 [MEDIUM] CVE-2020-14168: The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, fro
The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to access outgoing emails between a Jira instance and the SMTP server via man-in-the-middle (MITM) vulnerability.
nvd
CVE-2019-20897P4MEDIUMCVSS 6.5≥ 8.6.0, < 8.6.2≥ 8.7.0, < 8.7.12020-07-13
CVE-2019-20897 [MEDIUM] CWE-434 CVE-2019-20897: The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remot
The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2024-21685P4MEDIUMCVSS 6.5≥ 9.4.0, < 9.4.21≥ 9.12.0, < 9.12.8+1 more2024-06-18
CVE-2024-21685 [MEDIUM] CWE-200 CVE-2024-21685: This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, an
This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center.
This Information Disclosure vulnerability, with a CVSS Score of 7.4, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability which has high impact to confidential
nvd