Логотип exploitDog
product: "jira"
Консоль
Логотип exploitDog

exploitDog

product: "jira"

Количество 306

Количество 306

github логотип

GHSA-c7mj-gq36-7x33

около 3 лет назад

Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before 8.12.1.

EPSS: Низкий
github логотип

GHSA-c774-74r4-2fqx

около 3 лет назад

The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-c5g8-ww6r-9vf8

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname (Full Name) parameter in the ViewProfile page or (2) returnUrl parameter in a form, as demonstrated using secure/AddComment!default.jspa (aka "Add Comment").

EPSS: Низкий
github логотип

GHSA-9fv9-67fw-mfp3

около 3 лет назад

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

EPSS: Низкий
github логотип

GHSA-99xr-4v8h-g5x7

больше 3 лет назад

JIRA Enterprise Edition before 3.12.1 allows remote attackers to delete another user's shared filter via a modified filter ID.

EPSS: Низкий
github логотип

GHSA-99qg-2w8q-6fqv

около 3 лет назад

The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted URL that is dynamically transformed into method calls, aka "WebWork 1 Parameter Injection Hole."

EPSS: Низкий
github логотип

GHSA-98m4-m2c3-qxgq

около 3 лет назад

Jenkins JIRA Plugin allows users to select and use credentials with System scope

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8wr9-r69x-g268

около 3 лет назад

The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

EPSS: Высокий
github логотип

GHSA-8r3m-p3xg-5qjq

около 3 лет назад

The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7xqw-49vx-86cm

около 3 лет назад

Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.

EPSS: Средний
github логотип

GHSA-7xjr-vjjg-5v8v

около 3 лет назад

Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-7vh9-vmfj-h37x

около 3 лет назад

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-7q8f-h72p-5h7x

около 3 лет назад

Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in Atlassian JIRA before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via the name parameter to secure/admin/user/DeleteUser!default.jspa.

EPSS: Низкий
github логотип

GHSA-7p7w-89xm-52j5

около 3 лет назад

The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-77v5-v9v5-mwpv

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-73j8-52vp-m475

около 3 лет назад

Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qm4-89p4-vrg6

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a direct request to secure/ConfigureReleaseNote.jspa, which are not sanitized before being returned in an error page.

EPSS: Низкий
github логотип

GHSA-344x-g5pc-f6x4

больше 3 лет назад

secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-#156 allows remote attackers to obtain sensitive information via unspecified manipulations of the projectId parameter, which displays the installation path and other system information in an error message.

EPSS: Низкий
nvd логотип

CVE-2023-49653

больше 1 года назад

Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-29041

больше 3 лет назад

Jenkins Jira Plugin 3.7 and earlier, except 3.6.1, does not escape the name and description of Jira Issue and Jira Release Version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 6.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-c7mj-gq36-7x33

Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before 8.12.1.

0%
Низкий
около 3 лет назад
github логотип
GHSA-c774-74r4-2fqx

The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-c5g8-ww6r-9vf8

Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname (Full Name) parameter in the ViewProfile page or (2) returnUrl parameter in a form, as demonstrated using secure/AddComment!default.jspa (aka "Add Comment").

0%
Низкий
около 3 лет назад
github логотип
GHSA-9fv9-67fw-mfp3

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

0%
Низкий
около 3 лет назад
github логотип
GHSA-99xr-4v8h-g5x7

JIRA Enterprise Edition before 3.12.1 allows remote attackers to delete another user's shared filter via a modified filter ID.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-99qg-2w8q-6fqv

The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted URL that is dynamically transformed into method calls, aka "WebWork 1 Parameter Injection Hole."

1%
Низкий
около 3 лет назад
github логотип
GHSA-98m4-m2c3-qxgq

Jenkins JIRA Plugin allows users to select and use credentials with System scope

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-8wr9-r69x-g268

The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

72%
Высокий
около 3 лет назад
github логотип
GHSA-8r3m-p3xg-5qjq

The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-7xqw-49vx-86cm

Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.

67%
Средний
около 3 лет назад
github логотип
GHSA-7xjr-vjjg-5v8v

Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-7vh9-vmfj-h37x

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-7q8f-h72p-5h7x

Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in Atlassian JIRA before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via the name parameter to secure/admin/user/DeleteUser!default.jspa.

1%
Низкий
около 3 лет назад
github логотип
GHSA-7p7w-89xm-52j5

The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.

CVSS3: 6.1
40%
Средний
около 3 лет назад
github логотип
GHSA-77v5-v9v5-mwpv

Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
около 3 лет назад
github логотип
GHSA-73j8-52vp-m475

Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-3qm4-89p4-vrg6

Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a direct request to secure/ConfigureReleaseNote.jspa, which are not sanitized before being returned in an error page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-344x-g5pc-f6x4

secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-#156 allows remote attackers to obtain sensitive information via unspecified manipulations of the projectId parameter, which displays the installation path and other system information in an error message.

0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-49653

Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2022-29041

Jenkins Jira Plugin 3.7 and earlier, except 3.6.1, does not escape the name and description of Jira Issue and Jira Release Version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 6.4
18%
Средний
больше 3 лет назад

Уязвимостей на страницу