Show filters
110 Total Results
Displaying 61-70 of 110
Sort by:
Attacker Value
Unknown
CVE-2020-36235
Disclosure Date: February 04, 2021 (last updated November 28, 2024)
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
0
Attacker Value
Unknown
CVE-2020-36236
Disclosure Date: February 04, 2021 (last updated February 22, 2025)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
0
Attacker Value
Unknown
CVE-2021-26070
Disclosure Date: January 27, 2021 (last updated February 22, 2025)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
0
Attacker Value
Unknown
CVE-2020-29453
Disclosure Date: January 21, 2021 (last updated February 22, 2025)
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
0
Attacker Value
Unknown
CVE-2020-36231
Disclosure Date: January 21, 2021 (last updated February 22, 2025)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
0
Attacker Value
Unknown
CVE-2021-26069
Disclosure Date: January 21, 2021 (last updated February 22, 2025)
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations API endpoint. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0.
0
Attacker Value
Unknown
CVE-2020-29451
Disclosure Date: January 20, 2021 (last updated November 28, 2024)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.
0
Attacker Value
Unknown
CVE-2020-14181
Disclosure Date: September 16, 2020 (last updated February 22, 2025)
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0.
0
Attacker Value
Unknown
CVE-2020-14179
Disclosure Date: September 11, 2020 (last updated November 28, 2024)
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.
0
Attacker Value
Unknown
CVE-2020-14178
Disclosure Date: September 01, 2020 (last updated November 28, 2024)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.
0