Atlassian

Jira Server

135 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.02%
  • Veröffentlicht 15.04.2021 00:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:13

The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DO...

  • EPSS 0.46%
  • Veröffentlicht 15.04.2021 00:15:12
  • Zuletzt bearbeitet 21.11.2024 05:55:49

The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path o...

  • EPSS 0.33%
  • Veröffentlicht 15.04.2021 00:15:12
  • Zuletzt bearbeitet 21.11.2024 05:55:49

The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote anonymous attackers who can per...

  • EPSS 60.46%
  • Veröffentlicht 09.04.2021 02:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:13

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related setting...

  • EPSS 0.16%
  • Veröffentlicht 01.04.2021 03:15:14
  • Zuletzt bearbeitet 21.11.2024 05:55:48

The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software co...

  • EPSS 0.6%
  • Veröffentlicht 01.04.2021 03:15:13
  • Zuletzt bearbeitet 21.11.2024 05:29:07

The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or n...

  • EPSS 0.33%
  • Veröffentlicht 01.04.2021 03:15:13
  • Zuletzt bearbeitet 21.11.2024 05:29:12

The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members...

  • EPSS 0.85%
  • Veröffentlicht 22.03.2021 05:15:13
  • Zuletzt bearbeitet 21.11.2024 05:55:48

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions ar...

  • EPSS 2.47%
  • Veröffentlicht 22.03.2021 05:15:12
  • Zuletzt bearbeitet 21.11.2024 05:55:48

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations...

  • EPSS 82.63%
  • Veröffentlicht 22.02.2021 21:15:19
  • Zuletzt bearbeitet 21.11.2024 05:24:01

The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-I...