cbcvebase.

Atlassian Jira Data Center vulnerabilities

102 known vulnerabilities affecting atlassian/jira_data_center.

Total CVEs
102
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH21MEDIUM76LOW2

Vulnerabilities

Page 4 of 6
CVE-2020-36236P4MEDIUMCVSS 6.1≥ 8.6.0, < 8.13.3≥ unspecified, < 8.5.11+4 more2021-02-15
CVE-2020-36236 [MEDIUM] CWE-79 CVE-2020-36236: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15
nvd
CVE-2021-39111P4MEDIUMCVSS 6.1≥ 8.6.0, < 8.13.10≥ 8.14.0, < 8.18.2+5 more2021-08-30
CVE-2021-39111 [MEDIUM] CWE-79 CVE-2021-39111: The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into a field such as the desc
nvd
CVE-2021-26080P4MEDIUMCVSS 6.1fixed in 8.5.14≥ 8.6.0, < 8.13.6+6 more2021-06-07
CVE-2021-26080 [MEDIUM] CWE-79 CVE-2021-26080: EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version 8.13.6, and from 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
nvd
CVE-2021-26079P4MEDIUMCVSS 6.1≥ 8.6.0, < 8.13.7≥ 8.14.0, < 8.17.0+5 more2021-06-07
CVE-2021-26079 [MEDIUM] CWE-79 CVE-2021-26079: The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and f The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
nvd
CVE-2021-41310P4MEDIUMCVSS 6.1≥ unspecified, < 8.5.19≥ 8.6.0, < unspecified+3 more2021-11-01
CVE-2021-41310 [MEDIUM] CWE-79 CVE-2021-41310: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to injec Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11,
nvd
CVE-2020-14173P4MEDIUMCVSS 5.4≥ 8.6.0, < 8.6.2≥ 8.7.0, < 8.7.12020-07-03
CVE-2020-14173 [MEDIUM] CWE-79 CVE-2020-14173: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2021-26082P4MEDIUMCVSS 5.4≥ 8.6.0, < 8.13.6≥ 8.14.0, < 8.17.0+5 more2021-07-20
CVE-2021-26082 [MEDIUM] CWE-79 CVE-2021-26082: The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6 The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a stored cross site scripting vulnerability.
nvd
CVE-2020-36231P4MEDIUMCVSS 4.3≥ 8.6.0, < 8.13.2v8.13.3+3 more2021-02-02
CVE-2020-36231 [MEDIUM] CWE-639 CVE-2020-36231: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metada Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
nvd
CVE-2019-20106P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.5.4v8.6.02020-02-06
CVE-2019-20106 [MEDIUM] CWE-276 CVE-2019-20106: Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 befor Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
nvd
CVE-2020-4022P4MEDIUMCVSS 6.1≥ 8.6.0, < 8.8.2≥ 8.9.0, < 8.9.12020-07-01
CVE-2020-4022 [MEDIUM] CWE-79 CVE-2020-4022: The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6 The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a mixed multipart content type.
nvd
CVE-2021-41304P4MEDIUMCVSS 6.1≥ 8.14.0, < 8.20.2≥ unspecified, < 8.13.12+2 more2021-10-26
CVE-2021-41304 [MEDIUM] CWE-79 CVE-2021-41304: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to injec Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.2.
nvd
CVE-2021-26083P4MEDIUMCVSS 5.4≥ 8.6.0, < 8.13.6≥ 8.14.0, < 8.16.1+5 more2021-07-20
CVE-2021-26083 [MEDIUM] CWE-79 CVE-2021-26083: Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2020-14174P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.5.7≥ 8.6.0, < 8.9.2+1 more2020-07-13
CVE-2020-14174 [MEDIUM] CWE-639 CVE-2020-14174: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version
nvd
CVE-2021-39121P4MEDIUMCVSS 4.3≥ 8.6.0, < 8.13.10≥ 8.14.0, < 8.18.2+5 more2021-09-08
CVE-2021-39121 [MEDIUM] CVE-2021-39121: Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to e Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before version 8.5.18, from version 8.6.0 before 8.13.10, and from version 8.14.0 before 8.1
nvd
CVE-2019-20414P4MEDIUMCVSS 5.4≥ 8.0.0, < 8.4.22020-06-29
CVE-2019-20414 [MEDIUM] CWE-79 CVE-2019-20414: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
nvd
CVE-2020-4021P4MEDIUMCVSS 5.4≥ 8.0.0, < 8.5.5≥ 8.6.0, < 8.8.12020-06-01
CVE-2020-4021 [MEDIUM] CWE-79 CVE-2020-4021: Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data C Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.
nvd
CVE-2020-4024P4MEDIUMCVSS 5.4≥ 8.6.0, < 8.8.2≥ 8.9.0, < 8.9.12020-07-01
CVE-2020-4024 [MEDIUM] CWE-79 CVE-2020-4024: The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6 The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a vnd.wap.xhtml+xml content type.
nvd
CVE-2020-4029P4MEDIUMCVSS 4.3≥ 8.6.0, < 8.7.2≥ 8.8.0, < 8.8.12020-07-01
CVE-2020-4029 [MEDIUM] CVE-2020-4029: The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center befor The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability.
nvd
CVE-2019-20404P4MEDIUMCVSS 4.3≥ 8.2.4, < 8.6.0≥ 8.6.1, < 8.7.02020-02-06
CVE-2019-20404 [MEDIUM] CVE-2019-20404: The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote at The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
nvd
CVE-2019-20100P4MEDIUMCVSS 4.7≥ 7.0.0, < 8.5.4≥ 8.5.5, < 8.6.22020-02-12
CVE-2019-20100 [MEDIUM] CWE-352 CVE-2019-20100: The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The follo The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.2, and from version 7.1.0 before version 7.1.3. The vulnerable plugin is
nvd
Atlassian Jira Data Center vulnerabilities | cvebase