Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Center HIGH 7.5
CVE-2021-39123

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Deni…

Fix: 8.16.0+
Fix from $1,950 2021-09-14
Data Center MEDIUM 5.3
CVE-2021-39118

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeratio…

Fix: 8.19.0+
Fix from $1,600 2021-09-14
Data Center MEDIUM 5.3
CVE-2019-20101

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulne…

Fix: 8.13.3+
Fix from $1,600 2021-09-14
Data Center MEDIUM 5.3
CVE-2021-39122

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulne…

Fix: 8.5.13 / 8.13.5+
Fix from $1,600 2021-09-08
Jira Data Center MEDIUM 5.5
CVE-2021-39116

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (D…

Fix: 8.13.14 / 8.19.0+
Fix from $1,600 2021-09-08
Jira Service Desk HIGH 7.2
CVE-2021-39115

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arb…

Fix: 4.13.9 / 4.18.0+
Fix from $1,950 2021-09-01
Data Center MEDIUM 5.3
CVE-2021-39119

Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even afte…

Fix: 8.19.0+
Fix from $1,600 2021-09-01
Atlasboard HIGH 7.5
CVE-2021-39109

The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traversal vu…

Fix: 1.1.9+
Fix from $1,950 2021-09-01
Confluence Data Center CRITICAL 9.8
CVE-2021-26084 KEVEPSS 100%

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to exe…

Fix: 6.13.23 / 7.4.11+
Fix from $2,300 2021-08-30
Data Center HIGH 7.5
CVE-2021-39113

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing perm…

Fix: 8.13.9 / 8.18.0+
Fix from $1,950 2021-08-30
Data Center MEDIUM 6.1
CVE-2021-39111

The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 al…

Fix: 8.5.18 / 8.13.10+
Fix from $1,600 2021-08-30
Jira Data Center MEDIUM 5.3
CVE-2021-26086 KEVEPSS 100%

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the …

Fix: 8.5.14 / 8.13.6+
Fix from $1,600 2021-08-16
Confluence Data Center MEDIUM 5.3
CVE-2021-26085 KEVEPSS 100%

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vuln…

Fix: 7.4.10 / 7.12.3+
Fix from $1,600 2021-08-03
Saml Single Sign On CRITICAL 9.8
CVE-2021-37843

The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no othe…

Fix: 2.5.9 / 3.5.6+
Fix from $2,300 2021-08-02
Data Center HIGH 8.8
CVE-2017-18113

The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system admi…

Fix: 8.18.1+
Fix from $1,950 2021-08-02
Jira Data Center CRITICAL 9.8
CVE-2020-36239EPSS 47%

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.1…

Fix: 4.5.16 / 4.13.8+
Fix from $2,300 2021-07-29
Data Center MEDIUM 5.4
CVE-2021-26082

The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before …

Fix: 8.5.14 / 8.13.6+
Fix from $1,600 2021-07-20
Data Center MEDIUM 5.4
CVE-2021-26083

Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 bef…

Fix: 8.5.14 / 8.13.6+
Fix from $1,600 2021-07-20
Data Center MEDIUM 5.3
CVE-2021-26081

REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1…

Fix: 8.5.14 / 8.13.6+
Fix from $1,600 2021-07-20
Data Center MEDIUM 6.1
CVE-2021-26078

The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from ver…

Fix: 8.5.14 / 8.13.6+
Fix from $1,600 2021-06-07
Data Center MEDIUM 6.1
CVE-2021-26079

The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from…

Fix: 8.5.15 / 8.13.7+
Fix from $1,600 2021-06-07
Jira Data Center MEDIUM 6.1
CVE-2021-26080

EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version 8.13.6, and from 8.14.0 befo…

Fix: 8.5.14 / 8.13.6+
Fix from $1,600 2021-06-07
Data Center MEDIUM 5.3
CVE-2020-36289EPSS 99%

Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabili…

Fix: 8.5.13 / 8.13.5+
Fix from $1,600 2021-05-12
Connect Spring Boot HIGH 8.8
CVE-2021-26077

Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Sp…

Fix: 2.1.3 / 2.1.5+
Fix from $1,950 2021-05-10
Confluence Data Center MEDIUM 5.4
CVE-2020-29444

Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripti…

Fix: 7.11.0+
Fix from $1,600 2021-05-07
Connect Express HIGH 7.7
CVE-2021-26073

Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for …

Fix: 6.6.0+
Fix from $1,950 2021-04-16
Connect Spring Boot MEDIUM 6.5
CVE-2021-26074

Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring…

Fix: 2.1.3+
Fix from $1,600 2021-04-16
Data Center MEDIUM 6.1
CVE-2020-36288

The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version…

Fix: 8.5.12 / 8.13.4+
Fix from $1,600 2021-04-15
Data Center MEDIUM 5.3
CVE-2020-36287EPSS 9%

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from ve…

Fix: 8.13.5 / 8.15.1+
Fix from $1,600 2021-04-09
Data Center MEDIUM 5.3
CVE-2020-36238

The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.…

Fix: 8.5.13 / 8.13.5+
Fix from $1,600 2021-04-01