Atlassian

Jira Server

135 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.06%
  • Veröffentlicht 22.10.2025 01:00:06
  • Zuletzt bearbeitet 05.12.2025 00:38:58

This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score ...

  • EPSS 0.06%
  • Veröffentlicht 20.05.2025 18:00:01
  • Zuletzt bearbeitet 12.06.2025 16:20:47

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server ...

  • EPSS 0.06%
  • Veröffentlicht 11.02.2025 18:15:18
  • Zuletzt bearbeitet 30.07.2025 17:20:40

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.

  • EPSS 0.98%
  • Veröffentlicht 18.06.2024 17:15:51
  • Zuletzt bearbeitet 17.03.2025 15:15:40

This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Information Disclosure vulnerability, with a CVSS Score of 7.4, allows an unauthenticated attacker to vi...

  • EPSS 94.05%
  • Veröffentlicht 21.05.2024 23:15:07
  • Zuletzt bearbeitet 12.05.2025 16:15:20

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute ar...

  • EPSS 2.79%
  • Veröffentlicht 10.08.2022 03:15:08
  • Zuletzt bearbeitet 21.11.2024 07:13:47

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions ar...

  • EPSS 3.88%
  • Veröffentlicht 01.08.2022 11:15:14
  • Zuletzt bearbeitet 21.11.2024 07:13:46

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator pe...

  • EPSS 0.28%
  • Veröffentlicht 20.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulner...

  • EPSS 0.07%
  • Veröffentlicht 20.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security...

  • EPSS 90.27%
  • Veröffentlicht 30.06.2022 06:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian...