Vulnerabilities > Atlassian > Jira Server > 7.13.1

DATE CVE VULNERABILITY TITLE RISK
2019-08-23 CVE-2019-8446 Incorrect Authorization vulnerability in Atlassian Jira Server
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
network
low complexity
atlassian CWE-863
5.3
2019-08-23 CVE-2019-8445 Missing Authorization vulnerability in Atlassian Jira Server
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
network
low complexity
atlassian CWE-862
5.3
2019-08-23 CVE-2019-8444 Cross-site Scripting vulnerability in Atlassian Jira Server
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.
network
low complexity
atlassian CWE-79
5.4
2019-08-23 CVE-2019-11589 Open Redirect vulnerability in Atlassian Jira Server
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.
network
low complexity
atlassian CWE-601
6.1
2019-08-13 CVE-2019-8448 Unspecified vulnerability in Atlassian Jira Server
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
network
low complexity
atlassian
5.3
2019-08-09 CVE-2019-11581 Injection vulnerability in Atlassian Jira Server
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions.
network
low complexity
atlassian CWE-74
critical
9.8
2019-05-03 CVE-2019-3400 Cross-site Scripting vulnerability in Atlassian Jira Server
The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter.
network
low complexity
atlassian CWE-79
6.1
2019-04-30 CVE-2018-20239 Cross-site Scripting vulnerability in Atlassian products
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter.
network
low complexity
atlassian CWE-79
5.4