Show filters
136 Total Results
Displaying 41-50 of 136
Sort by:
Attacker Value
Unknown
CVE-2020-36288
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused by parameter pollution.
0
Attacker Value
Unknown
CVE-2020-36287
Disclosure Date: April 09, 2021 (last updated February 22, 2025)
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.
0
Attacker Value
Unknown
CVE-2020-36238
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions check.
0
Attacker Value
Unknown
CVE-2020-36286
Disclosure Date: April 01, 2021 (last updated November 28, 2024)
The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field.
0
Attacker Value
Unknown
CVE-2021-26071
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2021-26068
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.
0
Attacker Value
Unknown
CVE-2020-36235
Disclosure Date: February 04, 2021 (last updated November 28, 2024)
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
0
Attacker Value
Unknown
CVE-2020-36236
Disclosure Date: February 04, 2021 (last updated February 22, 2025)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
0
Attacker Value
Unknown
CVE-2021-26070
Disclosure Date: January 27, 2021 (last updated February 22, 2025)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
0
Attacker Value
Unknown
CVE-2020-29453
Disclosure Date: January 21, 2021 (last updated February 22, 2025)
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
0