Vulnerabilities > Atlassian > Data Center > 8.5.18

DATE CVE VULNERABILITY TITLE RISK
2021-08-30 CVE-2021-39113 Insufficient Session Expiration vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature.
network
low complexity
atlassian CWE-613
5.0
2021-04-09 CVE-2020-36287 Missing Authorization vulnerability in Atlassian products
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.
network
low complexity
atlassian CWE-862
5.0
2021-03-22 CVE-2021-26070 Improper Authentication vulnerability in Atlassian Data Center and Jira
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource.
network
low complexity
atlassian CWE-287
6.4