Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jira vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2019-20409
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote malicious users to gain remote code execution if they were able to exploit a server side template injection vulnerability.
Atlassian Jira
Atlassian Jira Software Data Center
6.1
CVSSv3
CVE-2022-36801
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote malicious users to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8.
Atlassian Jira Data Center
Atlassian Jira Server
4.9
CVSSv3
CVE-2019-20402
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
Atlassian Jira
Atlassian Jira Software Data Center
4.3
CVSSv3
CVE-2019-20405
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote malicious users to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
Atlassian Jira Server
Atlassian Jira Data Center
4.3
CVSSv3
CVE-2019-20407
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote malicious users to view release version information in projects that they do not have access to through an missing authorisation check.
Atlassian Jira Server
Atlassian Jira Data Center
6.5
CVSSv3
CVE-2019-20418
Affected versions of Atlassian Jira Server and Data Center allow remote malicious users to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0.
Atlassian Jira
Atlassian Jira Software Data Center
6.5
CVSSv3
CVE-2021-43941
Affected versions of Atlassian Jira Server and Data Center allow remote malicious users to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The aff...
Atlassian Jira Server
Atlassian Jira Data Center
7.2
CVSSv3
CVE-2021-43944
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary...
Atlassian Jira Server
Atlassian Jira Data Center
5.3
CVSSv3
CVE-2020-14165
The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote malicious users to obtain information about custom project avatars names via an Improper authorization vulnerability.
Atlassian Jira
Atlassian Jira Software Data Center
6.1
CVSSv3
CVE-2020-14169
The quick search component in Atlassian Jira Server and Data Center prior to 8.9.1 allows remote malicious users to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability
Atlassian Jira
Atlassian Jira Software Data Center
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2024-35894
SQL
CVE-2024-5105
CVE-2014-100005
CVE-2024-35895
unauthorized
CVE-2024-22120
CVE-2024-35890
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »