Skip to main content

Vendor/product archive

atlassian / data_center CVEs

Beta · best-effort

39 CVEs tagged to atlassian / data_center0 Critical, 6 High, 31 Medium, 2 Low, 0 Unrated.

CVE-2021-43945

Published Feb 28, 2022

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43953

Published Feb 15, 2022

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Requ…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41312

Published Nov 3, 2021

Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39124

Published Sep 14, 2021

The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user int…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39123

Published Sep 14, 2021

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerabil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39118

Published Sep 14, 2021

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20101

Published Sep 14, 2021

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelis…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39119

Published Sep 1, 2021

Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoke…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39117

Published Aug 30, 2021

The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scr…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18113

Published Aug 2, 2021

The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their mali…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2