Skip to main content

Vendor/product archive

atlassian / jira CVEs

Beta · best-effort

143 CVEs tagged to atlassian / jira5 Critical, 19 High, 116 Medium, 3 Low, 0 Unrated.

CVE-2019-15013

Published Dec 18, 2019

The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8449

Published Sep 11, 2019

The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11588

Published Aug 23, 2019

The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11587

Published Aug 23, 2019

Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11586

Published Aug 23, 2019

The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to crea…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11585

Published Aug 23, 2019

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect us…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11584

Published Aug 23, 2019

The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in th…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20827

Published Aug 9, 2019

The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the count…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20826

Published Aug 9, 2019

The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11583

Published Jun 26, 2019

The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8443

Published May 22, 2019

The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obta…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8442

Published May 22, 2019

The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3403

Published May 22, 2019

The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attacke…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3402

Published May 22, 2019

The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3401

Published May 22, 2019

The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20824

Published May 3, 2019

The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cy…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20232

Published Feb 13, 2019

The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 143 CVEsPage 4 of 6