Vulnerabilities > Atlassian > Jira Server > 8.5.13
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-08 | CVE-2021-39116 | Unspecified vulnerability in Atlassian Jira Data Center and Jira Server Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the GIF Image Reader component. | 5.5 |
2021-08-16 | CVE-2021-26086 | Path Traversal vulnerability in Atlassian Jira Data Center and Jira Server Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. | 5.3 |
2021-06-07 | CVE-2021-26080 | Cross-site Scripting vulnerability in Atlassian Jira Data Center and Jira Server EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version 8.13.6, and from 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. | 6.1 |
2020-07-13 | CVE-2019-20900 | Cross-site Scripting vulnerability in Atlassian Jira Data Center and Jira Server Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. | 4.8 |
2020-07-13 | CVE-2019-20899 | Unspecified vulnerability in Atlassian products The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. | 5.3 |
2020-03-17 | CVE-2019-20407 | Missing Authorization vulnerability in Atlassian Jira Data Center and Jira Server The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check. | 4.3 |
2020-02-12 | CVE-2019-20100 | Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). | 4.7 |
2020-02-12 | CVE-2019-20099 | Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). | 4.3 |
2020-02-12 | CVE-2019-20098 | Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). | 4.3 |
2020-02-06 | CVE-2019-20405 | Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability. | 4.3 |