Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
atlassian jira vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2021-43944
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary...
Atlassian Jira Server
Atlassian Jira Data Center
4.8
CVSSv3
CVE-2021-43945
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affect...
Atlassian Data Center
Atlassian Jira
4.8
CVSSv3
CVE-2021-43943
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefault...
Atlassian Jira Service Management
4.3
CVSSv3
CVE-2021-43948
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote malicious users to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before vers...
Atlassian Jira Service Management
6.5
CVSSv3
CVE-2021-43941
Affected versions of Atlassian Jira Server and Data Center allow remote malicious users to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The aff...
Atlassian Jira Server
Atlassian Jira Data Center
4.3
CVSSv3
CVE-2021-43950
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote malicious users to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are befor...
Atlassian Jira Service Management
4.3
CVSSv3
CVE-2021-43953
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote malicious users to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The af...
Atlassian Data Center
Atlassian Jira
4.3
CVSSv3
CVE-2021-43952
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote malicious users to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions a...
Atlassian Jira Server
Atlassian Jira Data Center
4.3
CVSSv3
CVE-2021-43949
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote malicious users to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.
Atlassian Jira Service Management
4.3
CVSSv3
CVE-2021-43951
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote malicious users to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are be...
Atlassian Jira Service Management
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »