Skip to main content

Vendor/product archive

atlassian / jira_service_management CVEs

Beta · best-effort

15 CVEs tagged to atlassian / jira_service_management4 Critical, 3 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2023-22501

Published Feb 1, 2023

An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Ser…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2022-36800

Published Aug 3, 2022

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26137

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2022-26136

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2021-43943

Published Feb 24, 2022

Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43948

Published Feb 15, 2022

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorizati…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43950

Published Feb 15, 2022

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Acc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43951

Published Jan 10, 2022

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information D…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43949

Published Jan 10, 2022

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerabilit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1