Vulnerabilities > Atlassian > Jira Server > 7.13.4

DATE CVE VULNERABILITY TITLE RISK
2019-08-23 CVE-2019-8446 Incorrect Authorization vulnerability in Atlassian Jira Server
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
network
low complexity
atlassian CWE-863
5.3
2019-08-23 CVE-2019-8445 Missing Authorization vulnerability in Atlassian Jira Server
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
network
low complexity
atlassian CWE-862
5.3
2019-08-23 CVE-2019-8444 Cross-site Scripting vulnerability in Atlassian Jira Server
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.
network
low complexity
atlassian CWE-79
5.4
2019-08-23 CVE-2019-11589 Open Redirect vulnerability in Atlassian Jira Server
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.
network
low complexity
atlassian CWE-601
6.1
2019-08-09 CVE-2019-11581 Injection vulnerability in Atlassian Jira
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions.
network
low complexity
atlassian CWE-74
critical
9.8