Atlassian Jira Server vulnerabilities
159 known vulnerabilities affecting atlassian/jira_server.
Total CVEs
159
CISA KEV
2
actively exploited
Public exploits
16
Exploited in wild
7
Severity breakdown
CRITICAL5HIGH27MEDIUM124LOW3
Vulnerabilities
Page 6 of 8
CVE-2019-20106P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.5.4v8.6.02020-02-06
CVE-2019-20106 [MEDIUM] CWE-276 CVE-2019-20106: Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 befor
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
nvd
CVE-2019-11585P4MEDIUMCVSS 6.1≥ 8.0.0, < 8.2.3≥ 8.3.0, < 8.3.22019-08-23
CVE-2019-11585 [MEDIUM] CWE-601 CVE-2019-11585: The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
nvd
CVE-2019-20901P4MEDIUMCVSS 6.1v8.6.0≥ unspecified, < 8.5.2+2 more2020-07-13
CVE-2019-20901 [MEDIUM] CWE-601 CVE-2019-20901: The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 all
The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter.
nvd
CVE-2020-4022P4MEDIUMCVSS 6.1≥ 8.6.0, < 8.8.2≥ 8.9.0, < 8.9.12020-07-01
CVE-2020-4022 [MEDIUM] CWE-79 CVE-2020-4022: The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a mixed multipart content type.
nvd
CVE-2019-11589P4MEDIUMCVSS 6.1≥ 7.13.0, < 7.13.6≥ 8.0.0, < 8.2.3+1 more2019-08-23
CVE-2019-11589 [MEDIUM] CWE-601 CVE-2019-11589: The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before versio
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.
nvd
CVE-2018-13395P4MEDIUMCVSS 6.1≥ 7.7.0, < 7.7.5≥ 7.8.0, < 7.8.5+3 more2018-08-28
CVE-2018-13395 [MEDIUM] CWE-79 CVE-2018-13395: Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, f
Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerab
nvd
CVE-2021-41304P4MEDIUMCVSS 6.1≥ 8.14.0, < 8.20.2≥ unspecified, < 8.13.12+2 more2021-10-26
CVE-2021-41304 [MEDIUM] CWE-79 CVE-2021-41304: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to injec
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.2.
nvd
CVE-2020-14184P4MEDIUMCVSS 5.4≥ 8.6.0, < 8.12.3v8.13.0+5 more2020-10-12
CVE-2020-14184 [MEDIUM] CWE-79 CVE-2020-14184: Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaSc
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected versions are before 8.5.9, from version 8.6.0 before 8.12.3, and from version 8.13.0 before 8.13.1.
nvd
CVE-2018-13403P4MEDIUMCVSS 5.4≥ 7.7.0, ≤ 7.12.3≥ 7.13.0, < 7.13.12019-02-13
CVE-2018-13403 [MEDIUM] CWE-79 CVE-2018-13403: The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.
nvd
CVE-2021-26083P4MEDIUMCVSS 5.4≥ 8.6.0, < 8.13.6≥ 8.14.0, < 8.16.1+5 more2021-07-20
CVE-2021-26083 [MEDIUM] CWE-79 CVE-2021-26083: Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version
Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2019-20402P4MEDIUMCVSS 4.9≥ unspecified, < 8.6.02020-02-06
CVE-2019-20402 [MEDIUM] CVE-2019-20402: Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
nvd
CVE-2020-14174P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.5.7≥ 8.6.0, < 8.9.2+8 more2020-07-13
CVE-2020-14174 [MEDIUM] CWE-639 CVE-2020-14174: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version
nvd
CVE-2021-39121P4MEDIUMCVSS 4.3≥ 8.6.0, < 8.13.10≥ 8.14.0, < 8.18.2+5 more2021-09-08
CVE-2021-39121 [MEDIUM] CVE-2021-39121: Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to e
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before version 8.5.18, from version 8.6.0 before 8.13.10, and from version 8.14.0 before 8.1
nvd
CVE-2019-14996P4MEDIUMCVSS 6.1≥ 7.12.0, < 7.13.7≥ 8.0.0, < 8.3.32019-09-11
CVE-2019-14996 [MEDIUM] CWE-79 CVE-2019-14996: The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before ver
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
nvd
CVE-2017-14594P4MEDIUMCVSS 6.1≥ 7.3.0, < 7.6.12018-01-12
CVE-2017-14594 [MEDIUM] CWE-79 CVE-2017-14594: The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.
nvd
CVE-2018-5232P4MEDIUMCVSS 6.1≥ 7.7.0, < 7.10.12018-07-18
CVE-2018-5232 [MEDIUM] CWE-79 CVE-2018-5232: The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before ver
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.
nvd
CVE-2019-20414P4MEDIUMCVSS 5.4≥ 8.0.0, < 8.4.2≥ unspecified, < 7.13.9+2 more2020-06-29
CVE-2019-20414 [MEDIUM] CWE-79 CVE-2019-20414: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
nvd
CVE-2020-4021P4MEDIUMCVSS 5.4≥ 8.0.0, < 8.5.5≥ 8.6.0, < 8.8.12020-06-01
CVE-2020-4021 [MEDIUM] CWE-79 CVE-2020-4021: Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data C
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.
nvd
CVE-2020-4024P4MEDIUMCVSS 5.4≥ 8.6.0, < 8.8.2≥ 8.9.0, < 8.9.12020-07-01
CVE-2020-4024 [MEDIUM] CWE-79 CVE-2020-4024: The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a vnd.wap.xhtml+xml content type.
nvd
CVE-2018-20232P4MEDIUMCVSS 5.4≥ 7.7.0, < 7.13.12019-02-13
CVE-2018-20232 [MEDIUM] CWE-79 CVE-2018-20232: The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before versi
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting.
nvd