Vulnerabilities > Atlassian > Jira Server > 8.4.0

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-15013 Missing Authorization vulnerability in Atlassian Jira
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.
network
low complexity
atlassian CWE-862
4.0
2019-09-19 CVE-2019-15001 Code Injection vulnerability in Atlassian Jira Server
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerability through the use of a crafted PUT request.
network
low complexity
atlassian CWE-94
critical
9.0