Atlassian Jira Server vulnerabilities
159 known vulnerabilities affecting atlassian/jira_server.
Total CVEs
159
CISA KEV
2
actively exploited
Public exploits
16
Exploited in wild
7
Severity breakdown
CRITICAL5HIGH27MEDIUM124LOW3
Vulnerabilities
Page 2 of 8
CVE-2019-20409P3CRITICALCVSS 9.8≥ unspecified, < 8.8.02020-06-23
CVE-2019-20409 [CRITICAL] CWE-74 CVE-2019-20409: The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to vers
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
nvd
CVE-2019-15001P3HIGHCVSS 7.2≥ 7.0.10, < 7.6.16≥ 7.7.0, < 7.13.8+16 more2019-09-19
CVE-2019-15001 [HIGH] CWE-94 CVE-2019-15001: The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerabil
nvd
CVE-2025-22157P3HIGHCVSS 8.8≥ 9.12.0, < 9.12.20≥ 10.3.0, < 10.3.5+1 more2025-05-20
CVE-2025-22157 [HIGH] CWE-284 CVE-2025-22157: This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0,
This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions:
9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server
5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server
This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perf
nvd
CVE-2022-26137P3HIGHCVSS 8.8≥ 8.13.0, < 8.13.22≥ 8.14.0, < 8.20.10+1 more2022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
nvd
CVE-2017-18113P3HIGHCVSS 8.8≥ unspecified, < 8.18.12021-08-02
CVE-2017-18113 [HIGH] CWE-94 CVE-2017-18113: The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 al
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code Execution (RCE) vulnerability. The vulnerability allowed for various problematic OSWorkflow classes to be used as pa
nvd
CVE-2022-36801P3MEDIUMCVSS 6.1fixed in 8.20.8≥ unspecified, < 8.20.82022-08-10
CVE-2022-36801 [MEDIUM] CWE-79 CVE-2022-36801: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to injec
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8.
nvd
CVE-2021-43942P3MEDIUMCVSS 6.1≥ 8.14.0, < 8.20.3≥ unspecified, < 8.13.15+2 more2022-01-04
CVE-2021-43942 [MEDIUM] CWE-79 CVE-2021-43942: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. To exploit this issue, the attacker must trick a user into visiting a malicious website. The affected versions are befor
nvd
CVE-2021-43947P3HIGHCVSS 7.2≥ 8.14.0, < 8.20.3≥ unspecified, < 8.13.15+2 more2022-01-06
CVE-2021-43947 [HIGH] CVE-2021-43947: Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected versions are before version 8.13.15, and from ver
nvd
CVE-2019-8443P3HIGHCVSS 8.1≥ 8.0.0, < 8.0.4≥ 8.1.0, < 8.1.12019-05-22
CVE-2019-8443 [HIGH] CWE-287 CVE-2019-8443: The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, an
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access contro
nvd
CVE-2021-43944P3HIGHCVSS 7.2fixed in 8.13.15≥ 8.14.0, < 8.20.3+3 more2022-03-08
CVE-2021-43944 [HIGH] CWE-94 CVE-2021-43944: This issue exists to document that a security improvement in the way that Jira Server and Data Cente
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the
nvd
CVE-2021-39128P3HIGHCVSS 7.2fixed in 8.13.12≥ 8.14.0, < 8.19.1+3 more2021-09-16
CVE-2021-39128 [HIGH] CWE-1336 CVE-2021-39128: Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon al
Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-side template injection vulnerability in the Email Template feature. The affected versions of Jira Server or Data Center are before version 8.13.12, and fr
nvd
CVE-2021-41307P3HIGHCVSS 7.5≥ 8.14.0, < 8.20.0≥ unspecified, < 8.13.12+2 more2021-10-26
CVE-2021-41307 [HIGH] CWE-639 CVE-2021-41307: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie Chart Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0.
nvd
CVE-2021-39113P3HIGHCVSS 7.5≥ 8.14.0, < 8.18.0≥ unspecified, < 8.13.9+2 more2021-08-30
CVE-2021-39113 [HIGH] CWE-613 CVE-2021-39113: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to conti
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0.
nvd
CVE-2021-41312P3HIGHCVSS 7.5≥ unspecified, < 8.19.12021-11-03
CVE-2021-41312 [HIGH] CWE-287 CVE-2021-41312: Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.
nvd
CVE-2020-14178P3HIGHCVSS 7.5≥ 8.0.0, < 8.5.8≥ 8.6.0, < 8.12.0+5 more2020-09-01
CVE-2020-14178 [HIGH] CVE-2020-14178: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate proje
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.
nvd
CVE-2021-41306P3HIGHCVSS 7.5≥ 8.14.0, < 8.20.0≥ unspecified, < 8.13.12+2 more2021-10-26
CVE-2021-41306 [HIGH] CWE-639 CVE-2021-41306: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0.
nvd
CVE-2021-26070P3HIGHCVSS 7.2≥ 8.14.0, < 8.14.1≥ unspecified, < 8.13.3+2 more2021-03-22
CVE-2021-26070 [HIGH] CWE-287 CVE-2021-26070: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-th
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
nvd
CVE-2021-41311P3HIGHCVSS 7.5≥ unspecified, < 8.19.12021-12-08
CVE-2021-41311 [HIGH] CWE-287 CVE-2021-41311: Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an adminis
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.
nvd
CVE-2019-3399P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.22019-04-30
CVE-2019-3399 [HIGH] CWE-863 CVE-2019-3399: The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before versio
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.
nvd
CVE-2025-22167P3MEDIUMCVSS 6.5≥ 9.12.0, < 9.12.28≥ 10.3.0, < 10.3.12+1 more2025-10-22
CVE-2025-22167 [MEDIUM] CWE-22 CVE-2025-22167: This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0
This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by the Jira JVM process. Atlassian r
nvd