Show filters
136 Total Results
Displaying 101-110 of 136
Sort by:
Attacker Value
Unknown

CVE-2019-8447

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown

CVE-2019-8445

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
Attacker Value
Unknown

CVE-2019-11585

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
0
Attacker Value
Unknown

CVE-2019-11588

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown

CVE-2019-8446

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
Attacker Value
Unknown

CVE-2019-8448

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
0
Attacker Value
Unknown

CVE-2019-11581 — Atlassian JIRA Template injection vulnerability RCE

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
0
Attacker Value
Unknown

CVE-2019-8442

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
Attacker Value
Unknown

CVE-2019-3401

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
Attacker Value
Unknown

CVE-2019-8443

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.