Логотип exploitDog
product: "jira"
Консоль
Логотип exploitDog

exploitDog

product: "jira"
Atlassian JIRA

Atlassian JIRAпрограммный продукт, разработанный Atlassian, который позволяет отслеживать ошибки, проблемы и гибкое управление проектами.

Релизный цикл, информация об уязвимостях

Продукт: Atlassian JIRA
Вендор: atlassian

График релизов

9.129.139.149.159.169.1710.010.110.210.310.410.510.610.711.011.1202320242025202620272028

Недавние уязвимости Atlassian JIRA

Количество 306

github логотип

GHSA-wrhc-7rh5-4x28

больше 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.

EPSS: Низкий
github логотип

GHSA-xx63-7hgm-gmr7

больше 3 лет назад

Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.3, and from version 8.0.0 before 8.1.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cjm2-9754-2rcj

больше 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-pmcv-jjqh-3g6v

больше 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4r95-5hvx-m4wp

больше 3 лет назад

The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue Keys; Issue Types; Status Types. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-x364-jprj-74rw

больше 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPickerBrowser.jspa page. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x36q-hfg7-f4qc

больше 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the comment restriction feature. The affected versions are before version 7.6.17, from version 7.7.0 before 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pvrh-7mfr-7cr8

больше 3 лет назад

Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.

EPSS: Низкий
github логотип

GHSA-8vf6-jj8p-33f5

больше 3 лет назад

The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.

EPSS: Низкий
github логотип

GHSA-844c-8r3w-mhj6

больше 3 лет назад

Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-wrhc-7rh5-4x28

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx63-7hgm-gmr7

Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.3, and from version 8.0.0 before 8.1.0.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-cjm2-9754-2rcj

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pmcv-jjqh-3g6v

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4r95-5hvx-m4wp

The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue Keys; Issue Types; Status Types. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-x364-jprj-74rw

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPickerBrowser.jspa page. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-x36q-hfg7-f4qc

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the comment restriction feature. The affected versions are before version 7.6.17, from version 7.7.0 before 7.13.9, and from version 8.0.0 before 8.4.2.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-pvrh-7mfr-7cr8

Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8vf6-jj8p-33f5

The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-844c-8r3w-mhj6

Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться