Atlassian

Jira

142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 06.02.2020 03:15:10
  • Zuletzt bearbeitet 21.11.2024 04:38:24

Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.

  • EPSS 0.29%
  • Veröffentlicht 18.12.2019 04:15:14
  • Zuletzt bearbeitet 21.11.2024 04:27:52

The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to...

  • EPSS 0.21%
  • Veröffentlicht 08.11.2019 04:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:51

The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message m...

Exploit
  • EPSS 68.72%
  • Veröffentlicht 11.09.2019 14:15:12
  • Zuletzt bearbeitet 21.11.2024 04:49:55

The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

  • EPSS 0.14%
  • Veröffentlicht 23.08.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:21:23

Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (C...

  • EPSS 0.26%
  • Veröffentlicht 23.08.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:21:23

The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request for...

  • EPSS 0.23%
  • Veröffentlicht 23.08.2019 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:21:23

The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.

  • EPSS 0.25%
  • Veröffentlicht 23.08.2019 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:21:23

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a p...

  • EPSS 0.14%
  • Veröffentlicht 23.08.2019 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:21:23

The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerabilit...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 09.08.2019 20:15:10
  • Zuletzt bearbeitet 21.11.2024 04:02:16

The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.