Логотип exploitDog
product: "jira"
Консоль
Логотип exploitDog

exploitDog

product: "jira"
Atlassian JIRA

Atlassian JIRAпрограммный продукт, разработанный Atlassian, который позволяет отслеживать ошибки, проблемы и гибкое управление проектами.

Релизный цикл, информация об уязвимостях

Продукт: Atlassian JIRA
Вендор: atlassian

График релизов

9.119.129.139.149.159.169.1710.010.110.210.310.410.510.610.711.0202320242025202620272028

Недавние уязвимости Atlassian JIRA

Количество 306

nvd логотип

CVE-2017-16863

больше 7 лет назад

The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-18033

больше 7 лет назад

The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2017-16865

больше 7 лет назад

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-16864

больше 7 лет назад

The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-16862

больше 7 лет назад

The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2017-14594

больше 7 лет назад

The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5983

больше 8 лет назад

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-4319

больше 8 лет назад

Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-4318

больше 8 лет назад

Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2016-6285

больше 8 лет назад

Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2017-16863

The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-18033

The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.

CVSS3: 6.5
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-16865

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

CVSS3: 5.3
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-16864

The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-16862

The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-14594

The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-5983

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.

CVSS3: 9.8
5%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-4319

Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

CVSS3: 8.8
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-4318

Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.

CVSS3: 4.8
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-6285

Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад

Уязвимостей на страницу


Поделиться