Atlassian Jira Server vulnerabilities
159 known vulnerabilities affecting atlassian/jira_server.
Total CVEs
159
CISA KEV
2
actively exploited
Public exploits
16
Exploited in wild
7
Severity breakdown
CRITICAL5HIGH27MEDIUM124LOW3
Vulnerabilities
Page 1 of 8
CVE-2019-11581P1CRITICALCVSS 9.8KEVPoC≥ 4.4, < 7.6.14≥ 7.7.0, < 7.13.5+3 more2019-08-09
CVE-2019-11581 [CRITICAL] CWE-74 CVE-2019-11581: There was a server-side template injection vulnerability in Jira Server and Data Center, in the Cont
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 befo
nvd
CVE-2021-26086P1MEDIUMCVSS 5.3KEVPoCfixed in 8.5.14≥ 8.6.0, < 8.13.6+6 more2021-08-16
CVE-2021-26086 [MEDIUM] CWE-22 CVE-2021-26086: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
nvd
CVE-2022-0540P1CRITICALCVSS 9.8ExploitedPoCfixed in 8.13.8≥ 8.14.0, < 8.20.6+1 more2022-04-20
CVE-2022-0540 [CRITICAL] CWE-287 CVE-2022-0540: A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Manag
nvd
CVE-2024-21683P1HIGHCVSS 8.8ExploitedPoC≥ 9.4.0, < 9.4.21≥ 9.12.0, < 9.12.82024-05-21
CVE-2024-21683 [HIGH] CWE-94 CVE-2024-21683: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Conflu
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availabi
nvd
CVE-2019-8451P2MEDIUMCVSS 6.5ExploitedPoC≥ 7.6.0, < 8.4.02019-09-11
CVE-2019-8451 [MEDIUM] CWE-918 CVE-2019-8451: The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attacke
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.
nvd
CVE-2019-8442P1HIGHCVSS 7.5ExploitedPoC≥ 8.0.0, < 8.0.4≥ 8.1.0, < 8.1.12019-05-22
CVE-2019-8442 [HIGH] CVE-2019-8442: The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 b
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
nvd
CVE-2019-8446P1MEDIUMCVSS 5.3ExploitedPoC≥ 7.6, < 8.3.22019-08-23
CVE-2019-8446 [MEDIUM] CWE-863 CVE-2019-8446: The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enu
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
nvd
CVE-2020-14181P2MEDIUMCVSS 5.3PoC≥ 8.0.0, < 8.5.7≥ 8.6.0, < 8.12.0+5 more2020-09-17
CVE-2020-14181 [MEDIUM] CWE-200 CVE-2020-14181: Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerat
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0.
nvd
CVE-2020-36289P2MEDIUMCVSS 5.3PoC≥ 8.6.0, < 8.13.5≥ 8.14.0, < 8.15.1+5 more2021-05-12
CVE-2020-36289 [MEDIUM] CWE-863 CVE-2020-36289: Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerat
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
nvd
CVE-2020-14179P2MEDIUMCVSS 5.3PoCfixed in 8.5.8≥ 8.6.0, < 8.11.1+3 more2020-09-21
CVE-2020-14179 [MEDIUM] CVE-2020-14179: Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers t
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.
nvd
CVE-2019-3403P3MEDIUMCVSS 5.3PoC≥ 8.0.0, < 8.0.4≥ 8.1.0, < 8.1.12019-05-22
CVE-2019-3403 [MEDIUM] CWE-863 CVE-2019-3403: The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before v
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
nvd
CVE-2020-29453P3MEDIUMCVSS 5.3PoC≥ 8.5.10, < 8.5.11≥ 8.6.0, < 8.13.3+6 more2021-02-22
CVE-2020-29453 [MEDIUM] CWE-22 CVE-2020-29453: The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
nvd
CVE-2018-5230P3MEDIUMCVSS 6.1PoC≥ 7.7.0, < 7.7.4≥ 7.8.0, < 7.8.4+1 more2018-05-14
CVE-2018-5230 [MEDIUM] CWE-79 CVE-2018-5230: The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4,
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value
nvd
CVE-2019-3401P3MEDIUMCVSS 5.3PoC≥ 8.0.0, < 8.1.12019-05-22
CVE-2019-3401 [MEDIUM] CWE-863 CVE-2019-3401: The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
nvd
CVE-2022-26135P3MEDIUMCVSS 6.5≥ 8.0.0, < 8.13.22≥ 8.14.0, < 8.20.10+1 more2022-06-30
CVE-2022-26135 [MEDIUM] CWE-918 CVE-2022-26135: A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.
nvd
CVE-2022-36799P2HIGHCVSS 7.2fixed in 8.13.19≥ 8.14.0, < 8.20.7+6 more2022-08-01
CVE-2022-36799 [HIGH] CWE-94 CVE-2022-36799: This issue exists to document that a security improvement in the way that Jira Server and Data Cente
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the
nvd
CVE-2022-26136P2CRITICALCVSS 9.8≥ 8.13.0, < 8.13.22≥ 8.14.0, < 8.20.10+1 more2022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
nvd
CVE-2019-3402P3MEDIUMCVSS 6.1PoC≥ 8.0.0, < 8.1.12019-05-22
CVE-2019-3402 [MEDIUM] CWE-79 CVE-2019-3402: The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before v
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
nvd
CVE-2020-14172P2CRITICALCVSS 9.8≥ unspecified, < 7.13.0≥ 8.0.0, < unspecified+3 more2020-07-03
CVE-2020-14172 [CRITICAL] CWE-502 CVE-2020-14172: This issue exists to document that a security improvement in the way that Jira Server and Data Cente
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers to achieve remote code execution via insecure deserialization, if the
nvd
CVE-2021-26078P3MEDIUMCVSS 6.1PoC≥ 8.6.0, < 8.13.6≥ 8.14.0, < 8.16.1+5 more2021-06-07
CVE-2021-26078 [MEDIUM] CWE-79 CVE-2021-26078: The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
nvd
1 / 8Next →