Atlassian

Jira

158 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.32%
  • Veröffentlicht 22.09.2026 18:03:03
  • Zuletzt bearbeitet 29.09.2026 13:56:16

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept an unconstrained file_path and open the referenced server-local fil...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 22.09.2026 17:55:37
  • Zuletzt bearbeitet 29.09.2026 14:21:29

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence search uses an ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 22.09.2026 17:47:58
  • Zuletzt bearbeitet 29.09.2026 19:00:07

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connec...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 22.09.2026 17:46:30
  • Zuletzt bearbeitet 28.09.2026 13:35:22

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths. The server o...

  • EPSS 0.33%
  • Veröffentlicht 14.09.2026 19:49:03
  • Zuletzt bearbeitet 30.09.2026 17:51:56

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassia...

Medienbericht
  • EPSS 2.26%
  • Veröffentlicht 10.03.2026 18:53:41
  • Zuletzt bearbeitet 02.04.2026 13:52:39

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any directory b...

  • EPSS 0.58%
  • Veröffentlicht 28.02.2022 01:15:08
  • Zuletzt bearbeitet 21.11.2024 06:30:03

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConf...

  • EPSS 0.48%
  • Veröffentlicht 15.02.2022 03:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:04

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentati...

  • EPSS 4.12%
  • Veröffentlicht 06.01.2022 01:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:03

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of h...

  • EPSS 1.17%
  • Veröffentlicht 03.11.2021 04:15:09
  • Zuletzt bearbeitet 21.11.2024 06:26:01

Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication...