Atlassian Jira Data Center vulnerabilities
102 known vulnerabilities affecting atlassian/jira_data_center.
Total CVEs
102
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH21MEDIUM76LOW2
Vulnerabilities
Page 5 of 6
CVE-2019-20407P4MEDIUMCVSS 4.3≥ 8.4.1, < 8.5.3≥ 8.5.4, < 8.6.1+1 more2020-03-17
CVE-2019-20407 [MEDIUM] CWE-862 CVE-2019-20407: The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.
nvd
CVE-2020-29451P4MEDIUMCVSS 4.3≥ unspecified, < 8.5.11≥ 8.6.0, < unspecified+3 more2021-02-15
CVE-2020-29451 [MEDIUM] CVE-2020-29451: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.
nvd
CVE-2021-41313P4MEDIUMCVSS 4.3fixed in 8.20.7≥ unspecified, < 8.20.72021-11-01
CVE-2021-41313 [MEDIUM] CWE-285 CVE-2021-41313: Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote
Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are before version 8.20.7.
nvd
CVE-2021-39112P4MEDIUMCVSS 4.8≥ 8.6.0, < 8.13.7≥ 8.14.0, < 8.17.1+8 more2021-08-25
CVE-2021-39112 [MEDIUM] CWE-1022 CVE-2021-39112: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from version 8.14.0 before 8.17.1, and from version 8.18.0 before 8.18.1.
nvd
CVE-2021-43952P4MEDIUMCVSS 4.3fixed in 8.13.18≥ 8.20.0, < 8.20.6+1 more2022-02-15
CVE-2021-43952 [MEDIUM] CWE-352 CVE-2021-43952: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.
nvd
CVE-2021-26075P4MEDIUMCVSS 4.3≥ 8.6.0, < 8.13.4≥ 8.14.0, < 8.15.1+5 more2021-04-15
CVE-2021-26075 [MEDIUM] CVE-2021-26075: The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before ve
The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data directory via an information disclosure vulnerability in the error message when p
nvd
CVE-2019-20098P4MEDIUMCVSS 4.3≥ 7.6.15, < 8.5.4≥ 8.5.5, < 8.6.22020-02-12
CVE-2019-20098 [MEDIUM] CWE-352 CVE-2019-20098: The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before ve
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network wher
nvd
CVE-2019-20099P4MEDIUMCVSS 4.3≥ 7.6.15, < 8.5.4≥ 8.5.5, < 8.6.22020-02-12
CVE-2019-20099 [MEDIUM] CWE-352 CVE-2019-20099: The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before ver
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where
nvd
CVE-2019-15002P4MEDIUMCVSS 4.3≥ 7.6.4, ≤ 8.1.0≥ unspecified, < 8.1.02025-02-11
CVE-2019-15002 [MEDIUM] CWE-352 CVE-2019-15002: An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login
An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.
nvd
CVE-2021-39116P4MEDIUMCVSS 5.5fixed in 8.13.14≥ 8.14.0, < 8.19.0+3 more2021-09-08
CVE-2021-39116 [MEDIUM] CVE-2021-39116: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the appl
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the GIF Image Reader component. The affected versions are before version 8.13.14, and from version 8.14.0 before 8.19.0.
nvd
CVE-2020-36234P4MEDIUMCVSS 4.8≥ 8.14.0, < 8.15.0≥ unspecified, < 8.5.11+4 more2021-02-15
CVE-2020-36234 [MEDIUM] CWE-79 CVE-2020-36234: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
nvd
CVE-2020-4025P4MEDIUMCVSS 4.8≥ 8.6.0, < 8.8.2≥ 8.9.0, < 8.9.12020-07-01
CVE-2020-4025 [MEDIUM] CWE-79 CVE-2020-4025: The attachment download resource in Atlassian Jira Server and Data Center The attachment download re
The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a
nvd
CVE-2021-39117P4MEDIUMCVSS 4.8≥ unspecified, < 8.18.02021-08-30
CVE-2021-39117 [MEDIUM] CWE-79 CVE-2021-39117: The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allo
The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field.
nvd
CVE-2021-43945P4MEDIUMCVSS 4.8≥ unspecified, < 8.20.32022-02-28
CVE-2021-43945 [MEDIUM] CWE-79 CVE-2021-43945: Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Admi
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
nvd
CVE-2021-39124P4MEDIUMCVSS 4.3≥ unspecified, < 8.16.02021-09-14
CVE-2021-39124 [MEDIUM] CWE-352 CVE-2021-39124: The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.
nvd
CVE-2021-43953P4MEDIUMCVSS 4.3≥ unspecified, < 8.13.16≥ next of 8.14.0, < unspecified+1 more2022-02-15
CVE-2021-43953 [MEDIUM] CWE-352 CVE-2021-43953: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.
nvd
CVE-2019-20900P4MEDIUMCVSS 4.8≥ 8.2.1, < 8.7.02020-07-13
CVE-2019-20900 [MEDIUM] CWE-79 CVE-2019-20900: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are before version 8.7.0.
nvd
CVE-2019-20411P4MEDIUMCVSS 4.3≥ 7.7.0, < 7.13.9≥ 8.0.0, < 8.4.22020-06-29
CVE-2019-20411 [MEDIUM] CWE-352 CVE-2019-20411: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
nvd
CVE-2019-20415P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.1.02020-06-30
CVE-2019-20415 [MEDIUM] CWE-352 CVE-2019-20415: Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging
Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.3, and from version 8.0.0 before 8.1.0.
nvd
CVE-2019-20405P4MEDIUMCVSS 4.3≥ 7.13.0, < 8.6.02020-02-06
CVE-2019-20405 [MEDIUM] CWE-352 CVE-2019-20405: The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
nvd