Логотип exploitDog
product: "jira"
Консоль
Логотип exploitDog

exploitDog

product: "jira"
Atlassian JIRA

Atlassian JIRAпрограммный продукт, разработанный Atlassian, который позволяет отслеживать ошибки, проблемы и гибкое управление проектами.

Релизный цикл, информация об уязвимостях

Продукт: Atlassian JIRA
Вендор: atlassian

График релизов

9.109.119.129.139.149.159.169.1710.010.110.210.310.410.510.610.7202320242025202620272028

Недавние уязвимости Atlassian JIRA

Количество 305

github логотип

GHSA-v734-hjcr-pm54

около 3 лет назад

The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7vh9-vmfj-h37x

около 3 лет назад

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-j5pf-67fx-vj74

около 3 лет назад

The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w84x-75fx-fxm2

около 3 лет назад

The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-r798-mxm8-76rv

около 3 лет назад

Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-v45j-7q58-p636

около 3 лет назад

Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xm63-47g5-8r8h

около 3 лет назад

The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c774-74r4-2fqx

около 3 лет назад

The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-w89h-rg2q-xpj2

около 3 лет назад

The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-gh3c-5h89-f225

около 3 лет назад

The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-v734-hjcr-pm54

The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-7vh9-vmfj-h37x

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-j5pf-67fx-vj74

The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-w84x-75fx-fxm2

The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-r798-mxm8-76rv

Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-v45j-7q58-p636

Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xm63-47g5-8r8h

The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-c774-74r4-2fqx

The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-w89h-rg2q-xpj2

The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-gh3c-5h89-f225

The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter.

CVSS3: 6.1
0%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться