← Back

Jira

jira

Vendor: Atlassian • 142 CVEs

CVEs (142)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
4Jira
Jira Data CenterJira Server+1 more
Jun 17, 2026
Feb 6, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do no...Show more
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have pr...Show more
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.Show less
1Atlassian
8Bamboo
BitbucketConfluence+5 more
Jun 17, 2026
Nov 8, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorizat...Show more
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.Show less
1Atlassian
1Jira
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collectio...Show more
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via...Show more
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site reque...Show more
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may...Show more
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.Show less
1Atlassian
1Jira
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.
1Atlassian
1Jira
Nov 21, 2024
Aug 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter.
1Atlassian
1Jira
Nov 21, 2024
Aug 9, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.
1Atlassian
1Jira
Jun 17, 2026
Jun 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
1Atlassian
2Jira
Jira Server
Jun 17, 2026
May 22, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to...Show more
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
May 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira web...Show more
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
May 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrec...Show more
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
May 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabili...Show more
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
May 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
1Atlassian
1Jira
Nov 21, 2024
May 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Apr 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Feb 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability...Show more
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting.Show less