Atlassian Jira Data Center vulnerabilities

102 known vulnerabilities affecting atlassian/jira_data_center.

Total CVEs
102
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH22MEDIUM75LOW2

Vulnerabilities

Page 4 of 6
CVE-2020-36286MEDIUMCVSS 5.3≥ 8.6.0, < 8.13.5≥ 8.14.0, < 8.15.1+5 more2021-04-01
CVE-2020-36286 [MEDIUM] CVE-2020-36286: The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field.
cvelistv5nvd
CVE-2021-26071LOWCVSS 3.5≥ 8.6.0, < 8.13.5≥ 8.14.0, < 8.15.1+5 more2021-04-01
CVE-2021-26071 [LOW] CWE-352 CVE-2021-26071: The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from versi The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.
cvelistv5nvd
CVE-2021-26070HIGHCVSS 7.2≥ unspecified, < 8.13.3≥ 8.14.0, < unspecified+1 more2021-03-22
CVE-2021-26070 [HIGH] CWE-287 CVE-2021-26070: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-th Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
cvelistv5nvd
CVE-2021-26069MEDIUMCVSS 5.3≥ 8.14.0, < 8.15.0≥ unspecified, < 8.5.11+4 more2021-03-22
CVE-2021-26069 [MEDIUM] CWE-74 CVE-2021-26069: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations API endpoint. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and
cvelistv5nvd
CVE-2020-29453MEDIUMCVSS 5.3PoC≥ 8.14.0, < 8.15.0≥ unspecified, < 8.5.11+4 more2021-02-22
CVE-2020-29453 [MEDIUM] CWE-22 CVE-2020-29453: The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5. The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
cvelistv5nvd
CVE-2020-36237MEDIUMCVSS 5.3≥ unspecified, < 8.15.02021-02-15
CVE-2020-36237 [MEDIUM] CVE-2020-36237: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.
cvelistv5nvd
CVE-2020-29451MEDIUMCVSS 4.3≥ unspecified, < 8.5.11≥ 8.6.0, < unspecified+3 more2021-02-15
CVE-2020-29451 [MEDIUM] CVE-2020-29451: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.
cvelistv5nvd
CVE-2020-36236MEDIUMCVSS 6.1≥ 8.6.0, < 8.13.3≥ unspecified, < 8.5.11+4 more2021-02-15
CVE-2020-36236 [MEDIUM] CWE-79 CVE-2020-36236: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15
cvelistv5nvd
CVE-2020-36235MEDIUMCVSS 5.3≥ unspecified, < 8.13.2≥ 8.14.0, < unspecified+1 more2021-02-15
CVE-2020-36235 [MEDIUM] CVE-2020-36235: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
cvelistv5nvd
CVE-2020-36234MEDIUMCVSS 4.8≥ 8.14.0, < 8.15.0≥ unspecified, < 8.5.11+4 more2021-02-15
CVE-2020-36234 [MEDIUM] CWE-79 CVE-2020-36234: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
cvelistv5nvd
CVE-2020-36231MEDIUMCVSS 4.3≥ 8.6.0, < 8.13.2v8.13.3+3 more2021-02-02
CVE-2020-36231 [MEDIUM] CWE-639 CVE-2020-36231: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metada Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
cvelistv5nvd
CVE-2020-14179MEDIUMCVSS 5.3PoCfixed in 8.5.8≥ 8.6.0, < 8.11.12020-09-21
CVE-2020-14179 [MEDIUM] CVE-2020-14179: Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers t Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.
nvd
CVE-2020-14178HIGHCVSS 7.5≥ 8.0.0, < 8.5.8≥ 8.6.0, < 8.12.02020-09-01
CVE-2020-14178 [HIGH] CVE-2020-14178: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate proje Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.
nvd
CVE-2019-20899MEDIUMCVSS 5.3≥ 8.5.5, < 8.6.1≥ 8.6.2, < 8.7.02020-07-13
CVE-2019-20899 [MEDIUM] CVE-2019-20899: The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
nvd
CVE-2019-20897MEDIUMCVSS 6.5≥ 8.6.0, < 8.6.2≥ 8.7.0, < 8.7.12020-07-13
CVE-2019-20897 [MEDIUM] CWE-434 CVE-2019-20897: The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remot The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2019-20900MEDIUMCVSS 4.8≥ 8.2.1, < 8.7.02020-07-13
CVE-2019-20900 [MEDIUM] CWE-79 CVE-2019-20900: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are before version 8.7.0.
nvd
CVE-2020-14174MEDIUMCVSS 4.3≥ 8.0.0, < 8.5.7≥ 8.6.0, < 8.9.2+1 more2020-07-13
CVE-2020-14174 [MEDIUM] CWE-639 CVE-2020-14174: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version
nvd
CVE-2019-20419HIGHCVSS 7.8fixed in 8.5.5≥ 8.6.0, < 8.7.22020-07-03
CVE-2019-20419 [HIGH] CWE-427 CVE-2019-20419: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitra Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8.6.0 before 8.7.2.
nvd
CVE-2020-14173MEDIUMCVSS 5.4≥ 8.6.0, < 8.6.2≥ 8.7.0, < 8.7.12020-07-03
CVE-2020-14173 [MEDIUM] CWE-79 CVE-2020-14173: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2020-14167HIGHCVSS 7.5≥ 8.5.0, < 8.5.5≥ 8.8.0, < 8.8.2+1 more2020-07-01
CVE-2020-14167 [HIGH] CVE-2020-14167: The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the application's availability via an Denial of Service (DoS) vulnerability.
nvd