Show filters
136 Total Results
Displaying 101-110 of 136
Sort by:
Attacker Value
Unknown
CVE-2019-8447
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2019-8445
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
0
Attacker Value
Unknown
CVE-2019-11585
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
0
Attacker Value
Unknown
CVE-2019-11588
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2019-8446
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
0
Attacker Value
Unknown
CVE-2019-8448
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2019-11581 — Atlassian JIRA Template injection vulnerability RCE
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2019-8442
Disclosure Date: May 22, 2019 (last updated November 27, 2024)
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
0
Attacker Value
Unknown
CVE-2019-3401
Disclosure Date: May 22, 2019 (last updated November 27, 2024)
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
0
Attacker Value
Unknown
CVE-2019-8443
Disclosure Date: May 22, 2019 (last updated November 27, 2024)
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.
0