Atlassian Jira Software Data Center vulnerabilities
45 known vulnerabilities affecting atlassian/jira_software_data_center.
Total CVEs
45
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH9MEDIUM31
Vulnerabilities
Page 2 of 3
CVE-2019-20899P4MEDIUMCVSS 5.3fixed in 8.5.42020-07-13
CVE-2019-20899 [MEDIUM] CVE-2019-20899: The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
nvd
CVE-2019-20418P4MEDIUMCVSS 6.5fixed in 8.8.02020-07-03
CVE-2019-20418 [MEDIUM] CVE-2019-20418: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users f
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0.
nvd
CVE-2020-36235P4MEDIUMCVSS 5.3fixed in 8.13.2≥ 8.14.0, < 8.14.12021-02-15
CVE-2020-36235 [MEDIUM] CVE-2020-36235: Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
nvd
CVE-2021-39127P4MEDIUMCVSS 5.3fixed in 8.5.102021-10-21
CVE-2021-39127 [MEDIUM] CVE-2021-39127: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the q
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
nvd
CVE-2019-20412P4MEDIUMCVSS 5.3fixed in 7.13.92020-06-29
CVE-2019-20412 [MEDIUM] CWE-287 CVE-2019-20412: The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center all
The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue Keys; Issue Types; Status Types. The affected versions are before version 7
nvd
CVE-2021-41309P4MEDIUMCVSS 5.3fixed in 8.19.12021-12-08
CVE-2021-41309 [MEDIUM] CWE-287 CVE-2021-41309: Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Servi
Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the /plugins/servlet/audit/resource endpoint. The affected versions of Jira Server and Data Center are bef
nvd
CVE-2020-14165P4MEDIUMCVSS 5.3fixed in 8.9.02020-07-01
CVE-2020-14165 [MEDIUM] CVE-2020-14165: The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0
The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.
nvd
CVE-2020-36236P4MEDIUMCVSS 6.1fixed in 8.5.11≥ 8.14.0, < 8.15.02021-02-15
CVE-2020-36236 [MEDIUM] CWE-79 CVE-2020-36236: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15
nvd
CVE-2021-41310P4MEDIUMCVSS 6.1fixed in 8.5.19≥ 8.6.0, < 8.13.11+1 more2021-11-01
CVE-2021-41310 [MEDIUM] CWE-79 CVE-2021-41310: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to injec
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11,
nvd
CVE-2020-14173P4MEDIUMCVSS 5.4fixed in 8.5.42020-07-03
CVE-2020-14173 [MEDIUM] CWE-79 CVE-2020-14173: The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote
The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1.
nvd
CVE-2020-4028P4MEDIUMCVSS 5.3fixed in 8.9.12020-06-23
CVE-2020-4028 [MEDIUM] CWE-203 CVE-2020-4028: Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthe
Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.
nvd
CVE-2020-36231P4MEDIUMCVSS 4.3fixed in 8.5.102021-02-02
CVE-2020-36231 [MEDIUM] CWE-639 CVE-2020-36231: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metada
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
nvd
CVE-2019-20106P4MEDIUMCVSS 4.3fixed in 7.13.122020-02-06
CVE-2019-20106 [MEDIUM] CWE-276 CVE-2019-20106: Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 befor
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
nvd
CVE-2020-4022P4MEDIUMCVSS 6.1fixed in 8.5.52020-07-01
CVE-2020-4022 [MEDIUM] CWE-79 CVE-2020-4022: The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a mixed multipart content type.
nvd
CVE-2019-20402P4MEDIUMCVSS 4.9fixed in 8.6.02020-02-06
CVE-2019-20402 [MEDIUM] CVE-2019-20402: Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
nvd
CVE-2020-14174P4MEDIUMCVSS 4.3fixed in 7.13.162020-07-13
CVE-2020-14174 [MEDIUM] CWE-639 CVE-2020-14174: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version
nvd
CVE-2020-14169P4MEDIUMCVSS 6.1fixed in 8.9.12020-07-01
CVE-2020-14169 [MEDIUM] CWE-79 CVE-2020-14169: The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attac
The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability
nvd
CVE-2020-14164P4MEDIUMCVSS 6.1fixed in 8.8.22020-07-01
CVE-2020-14164 [MEDIUM] CWE-79 CVE-2020-14164: The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attack
The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.
nvd
CVE-2019-20414P4MEDIUMCVSS 5.4fixed in 7.13.92020-06-29
CVE-2019-20414 [MEDIUM] CWE-79 CVE-2019-20414: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrar
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
nvd
CVE-2020-4021P4MEDIUMCVSS 5.4fixed in 7.13.162020-06-01
CVE-2020-4021 [MEDIUM] CWE-79 CVE-2020-4021: Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data C
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.
nvd