Vulnerabilities > Atlassian > Jira Service Management > 4.15.1

DATE CVE VULNERABILITY TITLE RISK
2022-08-03 CVE-2022-36800 Unspecified vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint.
network
low complexity
atlassian
4.3
2022-06-30 CVE-2022-26135 Server-Side Request Forgery (SSRF) vulnerability in Atlassian products
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint.
network
low complexity
atlassian CWE-918
4.0
2022-04-20 CVE-2022-0540 Unspecified vulnerability in Atlassian Jira Data Center and Jira Service Management
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request.
network
low complexity
atlassian
critical
9.8
2022-02-24 CVE-2021-43943 Cross-site Scripting vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa.
network
atlassian CWE-79
3.5
2022-02-15 CVE-2021-43948 Unspecified vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature.
network
low complexity
atlassian
4.0
2022-02-15 CVE-2021-43950 Unspecified vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature.
network
low complexity
atlassian
4.0
2022-01-10 CVE-2021-43949 Information Exposure vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature.
network
low complexity
atlassian CWE-200
4.0
2022-01-10 CVE-2021-43951 Information Exposure vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature.
network
low complexity
atlassian CWE-200
4.0
2021-09-01 CVE-2021-39115 Code Injection vulnerability in Atlassian Jira Service Desk
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature.
network
low complexity
atlassian CWE-94
critical
9.0
2021-07-29 CVE-2020-36239 Missing Authentication for Critical Function vulnerability in Atlassian products
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability.
network
low complexity
atlassian CWE-306
7.5