CVE-2019-11588
- EPSS 0.26%
- Veröffentlicht 23.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:23
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request for...
CVE-2019-11589
- EPSS 0.27%
- Veröffentlicht 23.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:23
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site requ...
CVE-2019-8444
- EPSS 0.34%
- Veröffentlicht 23.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:49:54
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.
CVE-2019-8445
- EPSS 0.9%
- Veröffentlicht 23.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:49:55
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
CVE-2019-8446
- EPSS 70.18%
- Veröffentlicht 23.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:49:55
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
CVE-2019-8447
- EPSS 0.15%
- Veröffentlicht 23.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:49:55
The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.
CVE-2019-11585
- EPSS 0.25%
- Veröffentlicht 23.08.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:21:23
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a p...
CVE-2019-11586
- EPSS 0.14%
- Veröffentlicht 23.08.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:21:23
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerabilit...
CVE-2019-8448
- EPSS 0.37%
- Veröffentlicht 13.08.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:49:55
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
CVE-2019-11581
- EPSS 94.36%
- Veröffentlicht 09.08.2019 20:15:11
- Zuletzt bearbeitet 24.10.2025 13:39:05
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server o...