Vulnerabilities > Atlassian > Jira Server > 8.11.1

DATE CVE VULNERABILITY TITLE RISK
2020-10-12 CVE-2020-14184 Cross-site Scripting vulnerability in Atlassian Jira
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files.
network
low complexity
atlassian CWE-79
5.4
2020-09-17 CVE-2020-14181 Information Exposure vulnerability in Atlassian Jira
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint.
network
low complexity
atlassian CWE-200
5.3
2020-09-01 CVE-2020-14178 Unspecified vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint.
network
low complexity
atlassian
7.5