CVE-2019-11587
- EPSS 0.8%
- Veröffentlicht 23.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:23
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (C...
CVE-2019-11588
- EPSS 0.79%
- Veröffentlicht 23.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:23
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request for...
CVE-2019-11584
- EPSS 0.97%
- Veröffentlicht 23.08.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:21:23
The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.
CVE-2019-11585
- EPSS 1.22%
- Veröffentlicht 23.08.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:21:23
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a p...
CVE-2019-11586
- EPSS 0.65%
- Veröffentlicht 23.08.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:21:23
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerabilit...
CVE-2018-20826
- EPSS 0.85%
- Veröffentlicht 09.08.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:02:16
The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.
CVE-2018-20827
- EPSS 0.76%
- Veröffentlicht 09.08.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:02:16
The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter.
CVE-2019-11583
- EPSS 1.5%
- Veröffentlicht 26.06.2019 16:15:09
- Zuletzt bearbeitet 21.11.2024 04:21:23
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
CVE-2019-8442
- EPSS 59.83%
- Veröffentlicht 22.05.2019 18:29:02
- Zuletzt bearbeitet 21.11.2024 04:49:54
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF direct...
CVE-2019-8443
- EPSS 2.62%
- Veröffentlicht 22.05.2019 18:29:02
- Zuletzt bearbeitet 21.11.2024 04:49:54
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades admin...