Atlassian

Jira Server

135 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 06.02.2020 03:15:10
  • Zuletzt bearbeitet 21.11.2024 04:38:24

The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.

  • EPSS 0.29%
  • Veröffentlicht 18.12.2019 04:15:14
  • Zuletzt bearbeitet 21.11.2024 04:27:52

The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to...

  • EPSS 12.03%
  • Veröffentlicht 19.09.2019 15:15:15
  • Zuletzt bearbeitet 21.11.2024 04:27:51

The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote at...

  • EPSS 0.29%
  • Veröffentlicht 11.09.2019 14:15:12
  • Zuletzt bearbeitet 21.11.2024 04:49:55

Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripti...

  • EPSS 92.28%
  • Veröffentlicht 11.09.2019 14:15:12
  • Zuletzt bearbeitet 21.11.2024 04:49:55

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist ...

Exploit
  • EPSS 1.2%
  • Veröffentlicht 11.09.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:50

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

  • EPSS 0.34%
  • Veröffentlicht 11.09.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:50

The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName pa...

  • EPSS 0.33%
  • Veröffentlicht 11.09.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:50

The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Prox...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 11.09.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:50

The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.

  • EPSS 0.14%
  • Veröffentlicht 23.08.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:21:23

Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (C...