Atlassian Jira Server vulnerabilities
159 known vulnerabilities affecting atlassian/jira_server.
Total CVEs
159
CISA KEV
2
actively exploited
Public exploits
16
Exploited in wild
7
Severity breakdown
CRITICAL5HIGH27MEDIUM124LOW3
Vulnerabilities
Page 4 of 8
CVE-2018-13391P4MEDIUMCVSS 5.3≥ 7.7.0, < 7.7.5≥ 7.8.0, < 7.8.5+3 more2018-08-28
CVE-2018-13391 [MEDIUM] CWE-200 CVE-2018-13391: The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before v
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain th
nvd
CVE-2020-36238P4MEDIUMCVSS 5.3≥ 8.6.0, < 8.13.5≥ 8.14.0, < 8.15.1+5 more2021-04-01
CVE-2020-36238 [MEDIUM] CWE-863 CVE-2020-36238: The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions check.
nvd
CVE-2021-26081P4MEDIUMCVSS 5.3≥ 8.6.0, < 8.13.6≥ 8.14.0, < 8.16.1+5 more2021-07-20
CVE-2021-26081 [MEDIUM] CVE-2021-26081: REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 bef
REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to enumerate usernames via a Sensitive Data Exposure vulnerability in the `/rest/api/latest/user/avatar/temporary` endpoint.
nvd
CVE-2019-20400P4HIGHCVSS 7.8≥ 8.3.2, < 8.5.2≥ 8.5.3, < 8.6.0+1 more2020-02-06
CVE-2019-20400 [HIGH] CWE-427 CVE-2019-20400: The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a d
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.
nvd
CVE-2019-20418P4MEDIUMCVSS 6.5≥ unspecified, < 8.8.02020-07-03
CVE-2019-20418 [MEDIUM] CVE-2019-20418: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users f
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0.
nvd
CVE-2021-39126P4MEDIUMCVSS 6.5fixed in 8.5.10≥ 8.6.0, < 8.13.1+3 more2021-10-21
CVE-2021-39126 [MEDIUM] CWE-352 CVE-2021-39126: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in the referrer headers which discloses a user's CSRF token. The affected versions are before version 8.5.10, and from version 8.6.0 befo
nvd
CVE-2020-36235P4MEDIUMCVSS 5.3≥ 8.14.0, < 8.14.1≥ unspecified, < 8.13.2+2 more2021-02-15
CVE-2020-36235 [MEDIUM] CVE-2020-36235: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
nvd
CVE-2021-39118P4MEDIUMCVSS 5.3≥ unspecified, < 8.19.02021-09-14
CVE-2021-39118 [MEDIUM] CVE-2021-39118: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the us
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0.
nvd
CVE-2021-39125P4MEDIUMCVSS 5.3≥ 8.6.0, < 8.13.1≥ unspecified, < 8.5.10+2 more2021-09-14
CVE-2021-39125 [MEDIUM] CVE-2021-39125: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to disco
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
nvd
CVE-2019-20101P4MEDIUMCVSS 5.3≥ unspecified, < 8.13.3≥ 8.14.0, < unspecified+1 more2021-09-14
CVE-2019-20101 [MEDIUM] CVE-2019-20101: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist//check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
nvd
CVE-2021-39127P4MEDIUMCVSS 5.3≥ 8.6.0, < 8.13.1≥ unspecified, < 8.5.10+2 more2021-10-21
CVE-2021-39127 [MEDIUM] CVE-2021-39127: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the q
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
nvd
CVE-2020-36237P4MEDIUMCVSS 5.3≥ unspecified, < 8.15.02021-02-15
CVE-2020-36237 [MEDIUM] CVE-2020-36237: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.
nvd
CVE-2021-43941P4MEDIUMCVSS 6.5fixed in 8.13.5≥ 8.14.0, < 8.20.3+3 more2022-02-15
CVE-2021-43941 [MEDIUM] CWE-352 CVE-2021-43941: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20
nvd
CVE-2017-18104P4MEDIUMCVSS 5.9≥ 7.7.0, < 7.11.02018-07-24
CVE-2017-18104 [MEDIUM] CWE-200 CVE-2017-18104: The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.
nvd
CVE-2019-8445P4MEDIUMCVSS 5.3≥ 7.13.0, < 7.13.7≥ 8.0.0, < 8.3.22019-08-23
CVE-2019-8445 [MEDIUM] CWE-863 CVE-2019-8445: Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
nvd
CVE-2019-20412P4MEDIUMCVSS 5.3≥ 8.0.0, < 8.4.2≥ unspecified, < 7.13.9+2 more2020-06-29
CVE-2019-20412 [MEDIUM] CWE-287 CVE-2019-20412: The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center all
The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue Keys; Issue Types; Status Types. The affected versions are before version 7
nvd
CVE-2021-39122P4MEDIUMCVSS 5.3≥ 8.6.0, < 8.13.5≥ 8.14.0, < 8.15.1+5 more2021-09-08
CVE-2021-39122 [MEDIUM] CVE-2021-39122: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
nvd
CVE-2019-14998P4MEDIUMCVSS 6.5≥ 7.4.0, < 8.4.02019-09-11
CVE-2019-14998 [MEDIUM] CWE-352 CVE-2019-14998: The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before versio
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.
nvd
CVE-2018-20239P4MEDIUMCVSS 5.4fixed in 7.13.3≥ 8.0.0, < 8.1.02019-04-30
CVE-2018-20239 [MEDIUM] CWE-79 CVE-2018-20239: Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a pl
nvd
CVE-2019-8448P4MEDIUMCVSS 5.3≥ 7.11.0, < 7.13.4≥ 8.0.0, < 8.2.22019-08-13
CVE-2019-8448 [MEDIUM] CVE-2019-8448: The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 al
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
nvd