Show filters
136 Total Results
Displaying 41-50 of 136
Sort by:
Attacker Value
Unknown

CVE-2020-36288

Disclosure Date: April 14, 2021 (last updated February 22, 2025)
The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused by parameter pollution.
Attacker Value
Unknown

CVE-2020-36287

Disclosure Date: April 09, 2021 (last updated February 22, 2025)
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.
Attacker Value
Unknown

CVE-2020-36238

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions check.
Attacker Value
Unknown

CVE-2020-36286

Disclosure Date: April 01, 2021 (last updated November 28, 2024)
The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field.
Attacker Value
Unknown

CVE-2021-26071

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.
Attacker Value
Unknown

CVE-2021-26068

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.
Attacker Value
Unknown

CVE-2020-36235

Disclosure Date: February 04, 2021 (last updated November 28, 2024)
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
Attacker Value
Unknown

CVE-2020-36236

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
Attacker Value
Unknown

CVE-2021-26070

Disclosure Date: January 27, 2021 (last updated February 22, 2025)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
Attacker Value
Unknown

CVE-2020-29453

Disclosure Date: January 21, 2021 (last updated February 22, 2025)
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.