CVE-2017-14594
- EPSS 0.23%
- Veröffentlicht 12.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:13:10
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query...
CVE-2017-16862
- EPSS 0.17%
- Veröffentlicht 12.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:07
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.
CVE-2017-16864
- EPSS 0.23%
- Veröffentlicht 12.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:07
The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.
CVE-2017-5983
- EPSS 8.39%
- Veröffentlicht 10.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serializ...
CVE-2016-4318
- EPSS 0.17%
- Veröffentlicht 10.04.2017 03:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
CVE-2016-4319
- EPSS 0.17%
- Veröffentlicht 10.04.2017 03:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
CVE-2016-6285
- EPSS 0.76%
- Veröffentlicht 31.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
CVE-2014-2313
- EPSS 0.23%
- Veröffentlicht 09.03.2014 13:16:57
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.
CVE-2014-2314
- EPSS 66.82%
- Veröffentlicht 09.03.2014 13:16:57
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.
CVE-2013-5319
- EPSS 0.51%
- Veröffentlicht 20.08.2013 14:55:47
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in Atlassian JIRA before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via the name parameter to secure/admin/user/Del...