Vulnerabilities > Atlassian > Jira Server > 7.10.0

DATE CVE VULNERABILITY TITLE RISK
2018-08-28 CVE-2018-13391 Information Exposure vulnerability in Atlassian Jira and Jira Server
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain the email address of the reporter and assignee user of an issue despite the configured email visibility setting being set to hidden.
network
low complexity
atlassian CWE-200
5.0
2018-07-24 CVE-2017-18104 Information Exposure vulnerability in Atlassian Jira and Jira Server
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.
network
atlassian CWE-200
4.3
2018-07-18 CVE-2018-5232 Cross-site Scripting vulnerability in Atlassian Jira
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.
network
atlassian CWE-79
4.3
2018-07-16 CVE-2018-13387 Cross-site Scripting vulnerability in Atlassian Jira
The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7.10.0 before version 7.10.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter as the fix for CVE-2017-18039 was incomplete.
network
atlassian CWE-79
4.3