Atlassian Jira Software Server vulnerabilities

5 known vulnerabilities affecting atlassian/jira_software_server.

Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-22167HIGHCVSS 8.7v9.12.0 to 9.12.272025-10-22
CVE-2025-22167 [HIGH] CWE-22 CVE-2025-22167: This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0 This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by the Jira JVM process. Atlassian rec
cvelistv5nvd
CVE-2022-26136CRITICALCVSS 9.8≥ unspecified, < 8.13.22≥ 8.14.0, < unspecified+3 more2022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
cvelistv5nvd
CVE-2022-26137HIGHCVSS 8.8≥ unspecified, < 8.13.22≥ 8.14.0, < unspecified+3 more2022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
cvelistv5nvd
CVE-2022-26135MEDIUMCVSS 6.5≥ 8.0.0, < unspecified≥ unspecified, < 8.13.22+4 more2022-06-30
CVE-2022-26135 [MEDIUM] CWE-918 CVE-2022-26135: A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.
cvelistv5nvd
CVE-2022-0540CRITICALCVSS 9.8PoC≥ unspecified, < 8.13.18≥ 8.14.0, < unspecified+3 more2022-04-20
CVE-2022-0540 [CRITICAL] CWE-287 CVE-2022-0540: A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Manag
cvelistv5nvd