Логотип exploitDog
product: "jira"
Консоль
Логотип exploitDog

exploitDog

product: "jira"
Atlassian JIRA

Atlassian JIRAпрограммный продукт, разработанный Atlassian, который позволяет отслеживать ошибки, проблемы и гибкое управление проектами.

Релизный цикл, информация об уязвимостях

Продукт: Atlassian JIRA
Вендор: atlassian

График релизов

9.109.119.129.139.149.159.169.1710.010.110.210.310.410.510.610.7202320242025202620272028

Недавние уязвимости Atlassian JIRA

Количество 305

github логотип

GHSA-mjf6-gmwv-grxx

около 3 лет назад

The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.2, and from version 7.1.0 before version 7.1.3. The vulnerable plugin is used by Atlassian Jira Server and Data Center before version 8.7.0. An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2cw7-vx4f-3wmm

около 3 лет назад

Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wwjm-wrhr-958r

около 3 лет назад

Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.

EPSS: Низкий
github логотип

GHSA-hmpw-22jw-wcrr

около 3 лет назад

The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-98m4-m2c3-qxgq

около 3 лет назад

Jenkins JIRA Plugin allows users to select and use credentials with System scope

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p5r4-xgh7-j23r

около 3 лет назад

The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q82r-7f6x-3rcx

около 3 лет назад

The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qghg-mq98-mjr4

около 3 лет назад

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-8r3m-p3xg-5qjq

около 3 лет назад

The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-q32m-2p66-w443

около 3 лет назад

Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-mjf6-gmwv-grxx

The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.2, and from version 7.1.0 before version 7.1.3. The vulnerable plugin is used by Atlassian Jira Server and Data Center before version 8.7.0. An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.

CVSS3: 4.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-2cw7-vx4f-3wmm

Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-wwjm-wrhr-958r

Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.

0%
Низкий
около 3 лет назад
github логотип
GHSA-hmpw-22jw-wcrr

The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-98m4-m2c3-qxgq

Jenkins JIRA Plugin allows users to select and use credentials with System scope

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-p5r4-xgh7-j23r

The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-q82r-7f6x-3rcx

The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-qghg-mq98-mjr4

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-8r3m-p3xg-5qjq

The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-q32m-2p66-w443

Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).

CVSS3: 6.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться