CVE-2021-43945
- EPSS 0.22%
- Veröffentlicht 28.02.2022 01:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:03
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConf...
CVE-2021-43953
- EPSS 0.32%
- Veröffentlicht 15.02.2022 03:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:04
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentati...
- EPSS 1.81%
- Veröffentlicht 06.01.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:03
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of h...
CVE-2021-41312
- EPSS 0.32%
- Veröffentlicht 03.11.2021 04:15:09
- Zuletzt bearbeitet 21.11.2024 06:26:01
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication...
CVE-2021-41304
- EPSS 0.47%
- Veröffentlicht 26.10.2021 05:15:06
- Zuletzt bearbeitet 21.11.2024 06:26:00
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message. The affect...
CVE-2021-39125
- EPSS 0.48%
- Veröffentlicht 14.09.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 06:18:38
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are before version 8.5.10, and from vers...
CVE-2021-39124
- EPSS 0.17%
- Veröffentlicht 14.09.2021 05:15:10
- Zuletzt bearbeitet 21.11.2024 06:18:38
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted req...
CVE-2021-39118
- EPSS 0.59%
- Veröffentlicht 14.09.2021 05:15:09
- Zuletzt bearbeitet 21.11.2024 06:18:36
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0...
CVE-2021-39123
- EPSS 0.8%
- Veröffentlicht 14.09.2021 05:15:09
- Zuletzt bearbeitet 21.11.2024 06:18:37
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint. The af...
CVE-2019-20101
- EPSS 1.57%
- Veröffentlicht 14.09.2021 05:15:07
- Zuletzt bearbeitet 21.11.2024 04:38:03
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8....