Atlassian Jira Software Data Center vulnerabilities
45 known vulnerabilities affecting atlassian/jira_software_data_center.
Total CVEs
45
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH10MEDIUM30
Vulnerabilities
Page 1 of 3
CVE-2025-22167HIGHCVSS 8.7v11.0.0 to 11.0.1v10.3.0 to 10.3.11+1 more2025-10-22
CVE-2025-22167 [HIGH] CWE-22 CVE-2025-22167: This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0
This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by the Jira JVM process. Atlassian rec
cvelistv5nvd
CVE-2022-26136CRITICALCVSS 9.8≥ unspecified, < 8.13.22≥ 8.14.0, < unspecified+3 more2022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
cvelistv5nvd
CVE-2022-26137HIGHCVSS 8.8≥ unspecified, < 8.13.22≥ 8.14.0, < unspecified+3 more2022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
cvelistv5nvd
CVE-2022-26135MEDIUMCVSS 6.5≥ 8.0.0, < unspecified≥ unspecified, < 8.13.22+4 more2022-06-30
CVE-2022-26135 [MEDIUM] CWE-918 CVE-2022-26135: A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.
cvelistv5nvd
CVE-2022-0540CRITICALCVSS 9.8PoC≥ unspecified, < 8.13.18≥ 8.14.0, < unspecified+3 more2022-04-20
CVE-2022-0540 [CRITICAL] CWE-287 CVE-2022-0540: A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Manag
cvelistv5nvd
CVE-2021-41311HIGHCVSS 7.5fixed in 8.19.12021-12-08
CVE-2021-41311 [HIGH] CWE-287 CVE-2021-41311: Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an adminis
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.
nvd
CVE-2021-41309MEDIUMCVSS 5.3fixed in 8.19.12021-12-08
CVE-2021-41309 [MEDIUM] CWE-287 CVE-2021-41309: Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Servi
Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the /plugins/servlet/audit/resource endpoint. The affected versions of Jira Server and Data Center are bef
nvd
CVE-2021-41310MEDIUMCVSS 6.1fixed in 8.5.19≥ 8.6.0, < 8.13.11+1 more2021-11-01
CVE-2021-41310 [MEDIUM] CWE-79 CVE-2021-41310: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to injec
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11,
nvd
CVE-2021-41305HIGHCVSS 7.5fixed in 8.13.122021-10-26
CVE-2021-41305 [HIGH] CWE-639 CVE-2021-41305: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in Status Gadget. The affected versions are before version 8.13.12..
nvd
CVE-2021-41307HIGHCVSS 7.5fixed in 8.13.12≥ 8.14.0, < 8.20.02021-10-26
CVE-2021-41307 [HIGH] CWE-639 CVE-2021-41307: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie Chart Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0.
nvd
CVE-2021-41306HIGHCVSS 7.5fixed in 8.13.12≥ 8.14.0, < 8.20.02021-10-26
CVE-2021-41306 [HIGH] CWE-639 CVE-2021-41306: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0.
nvd
CVE-2021-41308MEDIUMCVSS 6.5fixed in 8.6.0≥ 8.14.0, < 8.20.12021-10-26
CVE-2021-41308 [MEDIUM] CWE-285 CVE-2021-41308: Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the `ReplicationSettings!default.jspa` endpoint. The affected versions are before version 8.6.0, from version 8.7.0 before 8.13.12, and from version 8
nvd
CVE-2021-39127MEDIUMCVSS 5.3fixed in 8.5.102021-10-21
CVE-2021-39127 [MEDIUM] CVE-2021-39127: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the q
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
nvd
CVE-2020-36239CRITICALCVSS 9.8≥ 6.3.0, < unspecified≥ unspecified, < 8.5.16+4 more2021-07-29
CVE-2020-36239 [CRITICAL] CWE-862 CVE-2020-36239: Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16,
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attack
cvelistv5nvd
CVE-2020-36236MEDIUMCVSS 6.1fixed in 8.5.11≥ 8.14.0, < 8.15.02021-02-15
CVE-2020-36236 [MEDIUM] CWE-79 CVE-2020-36236: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15
nvd
CVE-2020-36235MEDIUMCVSS 5.3fixed in 8.13.2≥ 8.14.0, < 8.14.12021-02-15
CVE-2020-36235 [MEDIUM] CVE-2020-36235: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
nvd
CVE-2020-36231MEDIUMCVSS 4.3fixed in 8.5.102021-02-02
CVE-2020-36231 [MEDIUM] CWE-639 CVE-2020-36231: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metada
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
nvd
CVE-2020-14178HIGHCVSS 7.5fixed in 7.13.72020-09-01
CVE-2020-14178 [HIGH] CVE-2020-14178: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate proje
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.
nvd
CVE-2019-20898HIGHCVSS 7.5fixed in 8.8.02020-07-13
CVE-2019-20898 [HIGH] CVE-2019-20898: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitiv
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.
nvd
CVE-2019-20899MEDIUMCVSS 5.3fixed in 8.5.42020-07-13
CVE-2019-20899 [MEDIUM] CVE-2019-20899: The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
nvd
1 / 3Next →