Логотип exploitDog
product: "jira"
Консоль
Логотип exploitDog

exploitDog

product: "jira"

Количество 305

Количество 305

fstec логотип

BDU:2020-04776

почти 5 лет назад

Уязвимость компонента «/ViewUserHover.jspa» системы отслеживания ошибок Jira, позволяющая нарушителю раскрыть учетные данные пользователей

CVSS3: 5.3
EPSS: Критический
fstec логотип

BDU:2020-00077

почти 6 лет назад

Уязвимость системы отслеживания ошибок Jira, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xpwh-g564-whc7

около 3 лет назад

Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-x4g8-qffq-qj3v

около 3 лет назад

The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-x467-qjmw-8pjc

около 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.

EPSS: Низкий
github логотип

GHSA-wwjm-wrhr-958r

около 3 лет назад

Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.

EPSS: Низкий
github логотип

GHSA-wrhc-7rh5-4x28

около 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.

EPSS: Низкий
github логотип

GHSA-wrfq-mh97-mvmc

около 3 лет назад

The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.

EPSS: Низкий
github логотип

GHSA-wh72-r77f-wj75

около 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in Status Gadget. The affected versions are before version 8.13.12..

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w893-8c37-cjx9

около 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vp8g-cgfg-r7f6

около 3 лет назад

The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-vm5f-v8rf-rwpx

около 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.

EPSS: Низкий
github логотип

GHSA-rvgw-wp23-6245

около 3 лет назад

The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-rmxv-fp7w-g6g9

около 3 лет назад

The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qrjc-5qcw-h9gg

около 3 лет назад

The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qghg-mq98-mjr4

около 3 лет назад

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-q82r-7f6x-3rcx

около 3 лет назад

The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q32m-2p66-w443

около 3 лет назад

Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pvrh-7mfr-7cr8

около 3 лет назад

Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.

EPSS: Низкий
github логотип

GHSA-pmwf-r7hc-gwpq

около 3 лет назад

The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVSS3: 5.3
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2020-04776

Уязвимость компонента «/ViewUserHover.jspa» системы отслеживания ошибок Jira, позволяющая нарушителю раскрыть учетные данные пользователей

CVSS3: 5.3
94%
Критический
почти 5 лет назад
fstec логотип
BDU:2020-00077

Уязвимость системы отслеживания ошибок Jira, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
94%
Критический
почти 6 лет назад
github логотип
GHSA-xpwh-g564-whc7

Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-x4g8-qffq-qj3v

The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-x467-qjmw-8pjc

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.

1%
Низкий
около 3 лет назад
github логотип
GHSA-wwjm-wrhr-958r

Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wrhc-7rh5-4x28

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wrfq-mh97-mvmc

The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wh72-r77f-wj75

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in Status Gadget. The affected versions are before version 8.13.12..

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-w893-8c37-cjx9

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-vp8g-cgfg-r7f6

The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

CVSS3: 6.1
33%
Средний
около 3 лет назад
github логотип
GHSA-vm5f-v8rf-rwpx

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.

0%
Низкий
около 3 лет назад
github логотип
GHSA-rvgw-wp23-6245

The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-rmxv-fp7w-g6g9

The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-qrjc-5qcw-h9gg

The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-qghg-mq98-mjr4

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-q82r-7f6x-3rcx

The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-q32m-2p66-w443

Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-pvrh-7mfr-7cr8

Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.

0%
Низкий
около 3 лет назад
github логотип
GHSA-pmwf-r7hc-gwpq

The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVSS3: 5.3
83%
Высокий
около 3 лет назад

Уязвимостей на страницу