Atlassian Jira Server vulnerabilities
159 known vulnerabilities affecting atlassian/jira_server.
Total CVEs
159
CISA KEV
2
actively exploited
Public exploits
16
Exploited in wild
7
Severity breakdown
CRITICAL5HIGH27MEDIUM124LOW3
Vulnerabilities
Page 8 of 8
CVE-2020-36234P4MEDIUMCVSS 4.8≥ 8.6.0, < 8.13.3≥ 8.14.0, < 8.15.0+5 more2021-02-15
CVE-2020-36234 [MEDIUM] CWE-79 CVE-2020-36234: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
nvd
CVE-2020-4025P4MEDIUMCVSS 4.8≥ 8.6.0, < 8.8.2≥ 8.9.0, < 8.9.12020-07-01
CVE-2020-4025 [MEDIUM] CWE-79 CVE-2020-4025: The attachment download resource in Atlassian Jira Server and Data Center The attachment download re
The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a
nvd
CVE-2021-39117P4MEDIUMCVSS 4.8≥ unspecified, < 8.18.02021-08-30
CVE-2021-39117 [MEDIUM] CWE-79 CVE-2021-39117: The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allo
The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field.
nvd
CVE-2021-43945P4MEDIUMCVSS 4.8≥ unspecified, < 8.20.32022-02-28
CVE-2021-43945 [MEDIUM] CWE-79 CVE-2021-43945: Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Admi
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
nvd
CVE-2019-14997P4MEDIUMCVSS 4.3≥ 7.13.0, < 8.4.02019-09-11
CVE-2019-14997 [MEDIUM] CWE-524 CVE-2019-14997: The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn de
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.
nvd
CVE-2021-39124P4MEDIUMCVSS 4.3≥ unspecified, < 8.16.02021-09-14
CVE-2021-39124 [MEDIUM] CWE-352 CVE-2021-39124: The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.
nvd
CVE-2021-43953P4MEDIUMCVSS 4.3≥ unspecified, < 8.13.16≥ next of 8.14.0, < unspecified+1 more2022-02-15
CVE-2021-43953 [MEDIUM] CWE-352 CVE-2021-43953: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.
nvd
CVE-2019-20900P4MEDIUMCVSS 4.8≥ 8.2.1, < 8.7.0≥ unspecified, < 8.7.02020-07-13
CVE-2019-20900 [MEDIUM] CWE-79 CVE-2019-20900: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are before version 8.7.0.
nvd
CVE-2019-8450P4MEDIUMCVSS 4.8≥ 7.13.0, < 7.13.6≥ 8.0.0, < 8.4.02019-09-11
CVE-2019-8450 [MEDIUM] CWE-79 CVE-2019-8450: Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 b
Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a custom field.
nvd
CVE-2019-20416P4MEDIUMCVSS 4.8≥ unspecified, < 8.3.02020-06-30
CVE-2019-20416 [MEDIUM] CWE-79 CVE-2019-20416: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.
nvd
CVE-2019-20411P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.4.2≥ unspecified, < 7.13.9+2 more2020-06-29
CVE-2019-20411 [MEDIUM] CWE-352 CVE-2019-20411: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
nvd
CVE-2019-20415P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.1.0≥ unspecified, < 7.13.3+2 more2020-06-30
CVE-2019-20415 [MEDIUM] CWE-352 CVE-2019-20415: Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging
Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.3, and from version 8.0.0 before 8.1.0.
nvd
CVE-2019-8447P4MEDIUMCVSS 4.3≥ 7.13.0, < 8.3.22019-08-23
CVE-2019-8447 [MEDIUM] CWE-352 CVE-2019-8447: The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the cre
The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2019-11586P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.2.3≥ 8.3.0, < 8.3.22019-08-23
CVE-2019-11586 [MEDIUM] CWE-352 CVE-2019-11586: The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2019-20405P4MEDIUMCVSS 4.3≥ 7.13.0, < 8.6.0≥ unspecified, < 8.6.02020-02-06
CVE-2019-20405 [MEDIUM] CWE-352 CVE-2019-20405: The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2021-26076P4LOWCVSS 3.7≥ 8.6.0, < 8.13.4≥ 8.14.0, < 8.15.1+5 more2021-04-15
CVE-2021-26076 [LOW] CVE-2021-26076: The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before
The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote anonymous attackers who can perform an attacker in the middle attack to learn which mode a user is editing in due to the cookie not being set w
nvd
CVE-2019-11588P4MEDIUMCVSS 4.3≥ 8.0.0, < 8.2.3≥ 8.3.0, < 8.3.22019-08-23
CVE-2019-11588 [MEDIUM] CWE-352 CVE-2019-11588: The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2021-26071P4LOWCVSS 3.5≥ 8.6.0, < 8.13.5≥ 8.14.0, < 8.15.1+5 more2021-04-01
CVE-2021-26071 [LOW] CWE-352 CVE-2021-26071: The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from versi
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2015-8481P4LOWCVSS 3.1v7.0.32016-01-08
CVE-2015-8481 [LOW] CWE-200 CVE-2015-8481: Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer at
Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote attackers to obtain sensitive information by updating a different issue that includes wiki markup fo
nvd
← Previous8 / 8