threat
engine
.sh
Back
·
··:··
Home
/
Product
/
atlassian jira software data center
Product
atlassian jira software data center
39 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2021-41311
< 8.19.1
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had it
7.5
HIGH
CVE-2021-41309
< 8.19.1
Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked t
5.3
MEDIUM
CVE-2021-41310
< 8.5.19
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript
6.1
MEDIUM
CVE-2021-41308
< 8.6.0
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the
6.5
MEDIUM
CVE-2021-41307
< 8.13.12
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private pro
7.5
HIGH
CVE-2021-41306
< 8.13.12
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter nam
7.5
HIGH
CVE-2021-41305
< 8.13.12
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects
7.5
HIGH
CVE-2021-39127
< 8.5.10
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint vi
5.3
MEDIUM
CVE-2020-36236
< 8.5.11
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cro
6.1
MEDIUM
CVE-2020-36235
< 8.13.2
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom
5.3
MEDIUM
CVE-2020-36231
< 8.5.10
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not h
4.3
MEDIUM
CVE-2020-14178
< 7.13.7
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Dis
7.5
HIGH
CVE-2020-14174
< 7.13.16
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insec
4.3
MEDIUM
CVE-2019-20899
< 8.5.4
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via
5.3
MEDIUM
CVE-2019-20898
< 8.8.0
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being au
7.5
HIGH
CVE-2019-20897
< 8.5.4
The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial
6.5
MEDIUM
CVE-2020-14173
< 8.5.4
The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary
5.4
MEDIUM
CVE-2020-14172
< 7.13.0
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has b
9.8
CRITICAL
CVE-2019-20418
< 8.8.0
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via
6.5
MEDIUM
CVE-2020-4029
< 8.5.5
The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 be
4.3
MEDIUM
CVE-2020-4025
< 8.5.5
The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Serve
4.8
MEDIUM
CVE-2020-4024
< 8.5.5
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.
5.4
MEDIUM
CVE-2020-4022
< 8.5.5
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.
6.1
MEDIUM
CVE-2020-14169
< 8.9.1
The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML
6.1
MEDIUM
CVE-2020-14168
< 7.13.14
The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from
5.9
MEDIUM
CVE-2020-14167
< 7.13.14
The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 befor
7.5
HIGH
CVE-2020-14165
< 8.9.0
The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obt
5.3
MEDIUM
CVE-2020-14164
< 8.8.2
The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML o
6.1
MEDIUM
CVE-2019-20416
< 8.3.0
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cro
4.8
MEDIUM
CVE-2019-20415
< 7.13.3
Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a
4.3
MEDIUM
CVE-2019-20414
< 7.13.9
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cro
5.4
MEDIUM
CVE-2019-20413
< 7.13.9
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a D
7.5
HIGH
CVE-2019-20412
< 7.13.9
The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumera
5.3
MEDIUM
CVE-2019-20410
< 7.6.17
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information
6.5
MEDIUM
CVE-2020-4028
< 8.9.1
Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login pa
5.3
MEDIUM
CVE-2019-20409
< 8.8.0
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attac
9.8
CRITICAL
CVE-2020-4021
< 7.13.16
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers t
5.4
MEDIUM
CVE-2019-20402
< 8.6.0
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user
4.9
MEDIUM
CVE-2019-20106
< 7.13.12
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 bef
4.3
MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin