CVE-2021-39126
- EPSS 0.33%
- Veröffentlicht 21.10.2021 03:15:07
- Zuletzt bearbeitet 21.11.2024 06:18:38
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in the referrer headers which discl...
CVE-2021-39128
- EPSS 0.71%
- Veröffentlicht 16.09.2021 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:18:38
Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-side template injection vulnerability in the Email Te...
CVE-2021-39122
- EPSS 0.48%
- Veröffentlicht 08.09.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:18:37
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from ve...
CVE-2021-39121
- EPSS 0.4%
- Veröffentlicht 08.09.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:18:37
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affec...
CVE-2021-39116
- EPSS 0.54%
- Veröffentlicht 08.09.2021 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:18:36
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the GIF Image Reader component. The affected versions are before version 8.13.14...
CVE-2021-39113
- EPSS 0.56%
- Veröffentlicht 30.08.2021 07:15:06
- Zuletzt bearbeitet 21.11.2024 06:18:35
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions ar...
CVE-2021-39111
- EPSS 0.42%
- Veröffentlicht 30.08.2021 07:15:06
- Zuletzt bearbeitet 21.11.2024 06:18:35
The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnera...
CVE-2021-39112
- EPSS 0.28%
- Veröffentlicht 25.08.2021 03:15:06
- Zuletzt bearbeitet 21.11.2024 06:18:35
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from vers...
CVE-2021-26086
- EPSS 94.19%
- Veröffentlicht 16.08.2021 01:15:06
- Zuletzt bearbeitet 24.10.2025 13:38:33
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before...
CVE-2020-36239
- EPSS 16.17%
- Veröffentlicht 29.07.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 05:29:07
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 befo...