Atlassian

Jira Service Management

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 94.05%
  • Veröffentlicht 21.05.2024 23:15:07
  • Zuletzt bearbeitet 12.05.2025 16:15:20

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute ar...

  • EPSS 1.95%
  • Veröffentlicht 01.02.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 07:44:56

An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write acce...

  • EPSS 0.2%
  • Veröffentlicht 03.08.2022 03:15:08
  • Zuletzt bearbeitet 21.11.2024 07:13:47

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected ve...

  • EPSS 0.28%
  • Veröffentlicht 26.07.2022 08:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:05

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature...

  • EPSS 0.28%
  • Veröffentlicht 20.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulner...

  • EPSS 0.07%
  • Veröffentlicht 20.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security...

  • EPSS 90.27%
  • Veröffentlicht 30.06.2022 06:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian...

  • EPSS 92.14%
  • Veröffentlicht 20.04.2022 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:38:52

A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later befor...

  • EPSS 0.52%
  • Veröffentlicht 24.02.2022 05:15:09
  • Zuletzt bearbeitet 21.11.2024 06:30:03

Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/...

  • EPSS 0.37%
  • Veröffentlicht 15.02.2022 04:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:03

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions a...