Vulnerabilities > Atlassian > Jira > 7.1.12

DATE CVE VULNERABILITY TITLE RISK
2020-02-06 CVE-2019-20106 Incorrect Default Permissions vulnerability in Atlassian products
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
network
low complexity
atlassian CWE-276
4.0
2019-12-18 CVE-2019-15013 Missing Authorization vulnerability in Atlassian Jira
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.
network
low complexity
atlassian CWE-862
4.0
2019-09-11 CVE-2019-8449 Missing Authentication for Critical Function vulnerability in Atlassian Jira
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
network
low complexity
atlassian CWE-306
5.0
2019-08-23 CVE-2019-11588 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira and Jira Server
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.
network
atlassian CWE-352
4.3
2019-08-23 CVE-2019-11587 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira and Jira Server
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).
network
atlassian CWE-352
4.3
2019-08-23 CVE-2019-11586 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.
network
atlassian CWE-352
4.3
2019-08-23 CVE-2019-11585 Open Redirect vulnerability in Atlassian Jira
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
network
atlassian CWE-601
5.8
2019-08-09 CVE-2019-11581 Injection vulnerability in Atlassian Jira and Jira Server
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions.
network
atlassian CWE-74
critical
9.3
2019-08-09 CVE-2018-20826 Incorrect Authorization vulnerability in Atlassian Jira
The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.
network
low complexity
atlassian CWE-863
4.3
2019-05-22 CVE-2019-8443 Improper Authentication vulnerability in Atlassian Jira and Jira Server
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.
network
atlassian CWE-287
6.8