Atlassian Jira Server And Data Center vulnerabilities

15 known vulnerabilities affecting atlassian/jira_server_and_data_center.

Total CVEs
15
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH1MEDIUM13

Vulnerabilities

Page 1 of 1
CVE-2021-43942MEDIUMCVSS 6.1fixed in 8.13.52022-01-04
CVE-2021-43942 [MEDIUM] CWE-79 CVE-2021-43942: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. To exploit this issue, the attacker must trick a user into visiting a malicious website. The affected versions are befor
nvd
CVE-2020-14167HIGHCVSS 7.5≥ unspecified, < 7.13.14≥ 8.5.0, < unspecified+5 more2020-07-01
CVE-2020-14167 [HIGH] CVE-2020-14167: The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the application's availability via an Denial of Service (DoS) vulnerability.
cvelistv5nvd
CVE-2020-4025MEDIUMCVSS 4.8≥ unspecified, < 8.5.5≥ 8.6.0, < unspecified+3 more2020-07-01
CVE-2020-4025 [MEDIUM] CWE-79 CVE-2020-4025: The attachment download resource in Atlassian Jira Server and Data Center The attachment download re The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a
cvelistv5nvd
CVE-2020-14164MEDIUMCVSS 6.1≥ unspecified, < 8.8.22020-07-01
CVE-2020-14164 [MEDIUM] CWE-79 CVE-2020-14164: The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attack The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.
cvelistv5nvd
CVE-2020-4022MEDIUMCVSS 6.1≥ unspecified, < 8.5.5≥ 8.6.0, < unspecified+3 more2020-07-01
CVE-2020-4022 [MEDIUM] CWE-79 CVE-2020-4022: The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6 The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a mixed multipart content type.
cvelistv5nvd
CVE-2020-4029MEDIUMCVSS 4.3≥ unspecified, < 8.5.5≥ 8.6.0, < unspecified+3 more2020-07-01
CVE-2020-4029 [MEDIUM] CVE-2020-4029: The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center befor The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability.
cvelistv5nvd
CVE-2020-4024MEDIUMCVSS 5.4≥ unspecified, < 8.5.5≥ 8.6.0, < unspecified+3 more2020-07-01
CVE-2020-4024 [MEDIUM] CWE-79 CVE-2020-4024: The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6 The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a vnd.wap.xhtml+xml content type.
cvelistv5nvd
CVE-2020-14165MEDIUMCVSS 5.3≥ unspecified, < 8.9.02020-07-01
CVE-2020-14165 [MEDIUM] CVE-2020-14165: The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.
cvelistv5nvd
CVE-2020-14168MEDIUMCVSS 5.9≥ unspecified, < 7.13.16≥ 8.5.0, < unspecified+5 more2020-07-01
CVE-2020-14168 [MEDIUM] CVE-2020-14168: The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, fro The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to access outgoing emails between a Jira instance and the SMTP server via man-in-the-middle (MITM) vulnerability.
cvelistv5nvd
CVE-2020-14169MEDIUMCVSS 6.1≥ unspecified, < 8.9.12020-07-01
CVE-2020-14169 [MEDIUM] CWE-79 CVE-2020-14169: The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attac The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability
cvelistv5nvd
CVE-2020-4028MEDIUMCVSS 5.3≥ unspecified, < 8.9.12020-06-23
CVE-2020-4028 [MEDIUM] CWE-203 CVE-2020-4028: Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthe Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.
cvelistv5nvd
CVE-2020-4021MEDIUMCVSS 5.4≥ unspecified, < 8.5.5≥ 8.6.0, < unspecified+1 more2020-06-01
CVE-2020-4021 [MEDIUM] CWE-79 CVE-2020-4021: Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data C Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.
cvelistv5nvd
CVE-2019-20105MEDIUMCVSS 4.9≥ 7.13.8, < unspecified≥ unspecified, < 7.13.12+4 more2020-03-17
CVE-2019-20105 [MEDIUM] CWE-306 CVE-2019-20105: The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, fro The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access
cvelistv5nvd
CVE-2019-20106MEDIUMCVSS 4.3≥ unspecified, < 7.13.12≥ 8.4.1, < unspecified+3 more2020-02-06
CVE-2019-20106 [MEDIUM] CWE-276 CVE-2019-20106: Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 befor Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
cvelistv5nvd
CVE-2019-11581CRITICALCVSS 9.8KEVPoC≥ 4.4.0, < unspecified≥ unspecified, < 7.6.14+8 more2019-08-09
CVE-2019-11581 [CRITICAL] CWE-74 CVE-2019-11581: There was a server-side template injection vulnerability in Jira Server and Data Center, in the Cont There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 befo
cvelistv5nvd