Atlassian Jira Server vulnerabilities
159 known vulnerabilities affecting atlassian/jira_server.
Total CVEs
159
CISA KEV
2
actively exploited
Public exploits
16
Exploited in wild
7
Severity breakdown
CRITICAL5HIGH27MEDIUM124LOW3
Vulnerabilities
Page 7 of 8
CVE-2020-4029P4MEDIUMCVSS 4.3≥ 8.6.0, < 8.7.2≥ 8.8.0, < 8.8.12020-07-01
CVE-2020-4029 [MEDIUM] CVE-2020-4029: The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center befor
The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability.
nvd
CVE-2019-15005P4MEDIUMCVSS 4.3≥ unspecified, < 8.3.22019-11-08
CVE-2019-15005 [MEDIUM] CWE-862 CVE-2019-15005: The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivilege
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulne
nvd
CVE-2019-20404P4MEDIUMCVSS 4.3≥ 8.2.4, < 8.6.0≥ 8.6.1, < 8.7.0+1 more2020-02-06
CVE-2019-20404 [MEDIUM] CVE-2019-20404: The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote at
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
nvd
CVE-2019-3400P4MEDIUMCVSS 6.1fixed in 7.13.2≥ 8.0.0, < 8.0.22019-05-03
CVE-2019-3400 [MEDIUM] CWE-79 CVE-2019-3400: The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows
The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter.
nvd
CVE-2017-18102P4MEDIUMCVSS 5.4≥ 7.5.0, < 7.6.8≥ 7.7.0, < 7.7.1+1 more2018-04-17
CVE-2017-18102 [MEDIUM] CWE-79 CVE-2017-18102: The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remo
The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in nested wiki markup.
nvd
CVE-2019-8444P4MEDIUMCVSS 5.4≥ 7.7, < 7.13.6≥ 8.0.0, < 8.3.22019-08-23
CVE-2019-8444 [MEDIUM] CWE-79 CVE-2019-8444: The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.
nvd
CVE-2019-20100P4MEDIUMCVSS 4.7≥ 8.5.5, < 8.6.2≥ unspecified, < 8.7.02020-02-12
CVE-2019-20100 [MEDIUM] CWE-352 CVE-2019-20100: The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The follo
The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.2, and from version 7.1.0 before version 7.1.3. The vulnerable plugin is
nvd
CVE-2019-15013P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.4.3≥ 8.5.0, < 8.5.22019-12-18
CVE-2019-15013 [MEDIUM] CWE-862 CVE-2019-15013: The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 be
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.
nvd
CVE-2019-20407P4MEDIUMCVSS 4.3≥ 8.4.1, < 8.5.3≥ 8.5.4, < 8.6.1+1 more2020-03-17
CVE-2019-20407 [MEDIUM] CWE-862 CVE-2019-20407: The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.
nvd
CVE-2020-29451P4MEDIUMCVSS 4.3≥ 8.6.0, < 8.13.3≥ 8.14.0, < 8.14.1+5 more2021-02-15
CVE-2020-29451 [MEDIUM] CVE-2020-29451: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.
nvd
CVE-2021-41313P4MEDIUMCVSS 4.3fixed in 8.20.7≥ unspecified, < 8.20.72021-11-01
CVE-2021-41313 [MEDIUM] CWE-285 CVE-2021-41313: Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote
Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are before version 8.20.7.
nvd
CVE-2021-39112P4MEDIUMCVSS 4.8≥ 8.6.0, < 8.13.7≥ 8.14.0, < 8.17.1+8 more2021-08-25
CVE-2021-39112 [MEDIUM] CWE-1022 CVE-2021-39112: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from version 8.14.0 before 8.17.1, and from version 8.18.0 before 8.18.1.
nvd
CVE-2018-13404P4MEDIUMCVSS 4.1≥ 7.7.0, < 7.7.5≥ 7.8.0, ≤ 7.8.4+5 more2019-02-13
CVE-2018-13404 [MEDIUM] CWE-918 CVE-2018-13404: The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 b
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.
nvd
CVE-2021-43952P4MEDIUMCVSS 4.3fixed in 8.13.18≥ 8.20.0, < 8.20.6+1 more2022-02-15
CVE-2021-43952 [MEDIUM] CWE-352 CVE-2021-43952: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.
nvd
CVE-2021-26075P4MEDIUMCVSS 4.3≥ 8.6.0, < 8.13.4≥ 8.14.0, < 8.15.1+5 more2021-04-15
CVE-2021-26075 [MEDIUM] CVE-2021-26075: The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before ve
The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data directory via an information disclosure vulnerability in the error message when p
nvd
CVE-2020-14183P4MEDIUMCVSS 4.3≥ unspecified, < 7.13.18≥ 8.0.0, < unspecified+3 more2020-10-06
CVE-2020-14183 [MEDIUM] CWE-200 CVE-2020-14183: Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) priv
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 befor
nvd
CVE-2019-20098P4MEDIUMCVSS 4.3≥ 7.6.15, < 8.5.4≥ 8.5.5, < 8.6.2+1 more2020-02-12
CVE-2019-20098 [MEDIUM] CWE-352 CVE-2019-20098: The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before ve
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network wher
nvd
CVE-2019-20099P4MEDIUMCVSS 4.3≥ 7.6.15, < 8.5.4≥ 8.5.5, < 8.6.2+1 more2020-02-12
CVE-2019-20099 [MEDIUM] CWE-352 CVE-2019-20099: The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before ver
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where
nvd
CVE-2019-15002P4MEDIUMCVSS 4.3≥ 7.6.4, ≤ 8.1.0≥ unspecified, < 8.1.02025-02-11
CVE-2019-15002 [MEDIUM] CWE-352 CVE-2019-15002: An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login
An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.
nvd
CVE-2021-39116P4MEDIUMCVSS 5.5fixed in 8.13.14≥ 8.14.0, < 8.19.0+3 more2021-09-08
CVE-2021-39116 [MEDIUM] CVE-2021-39116: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the appl
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the GIF Image Reader component. The affected versions are before version 8.13.14, and from version 8.14.0 before 8.19.0.
nvd