Vulnerabilities > Atlassian > Jira > 8.5.19
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-15 | CVE-2020-36235 | Unspecified vulnerability in Atlassian Jira Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. | 5.3 |
2020-07-13 | CVE-2019-20898 | Unspecified vulnerability in Atlassian Jira Software Data Center Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. | 7.5 |
2020-07-03 | CVE-2019-20418 | Unspecified vulnerability in Atlassian Jira Software Data Center Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. | 6.5 |
2020-07-01 | CVE-2020-14169 | Cross-site Scripting vulnerability in Atlassian Jira The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability | 6.1 |
2020-07-01 | CVE-2020-14165 | Unspecified vulnerability in Atlassian Jira The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability. | 5.3 |
2020-07-01 | CVE-2020-14164 | Cross-site Scripting vulnerability in Atlassian Jira The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field. | 6.1 |
2020-07-01 | CVE-2019-20408 | Server-Side Request Forgery (SSRF) vulnerability in Atlassian Jira The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class. | 5.3 |
2020-06-23 | CVE-2020-4028 | Information Exposure Through Discrepancy vulnerability in Atlassian Jira Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability. | 5.3 |
2020-06-23 | CVE-2019-20409 | Injection vulnerability in Atlassian Jira Software Data Center The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability. | 9.8 |
2020-02-06 | CVE-2019-20402 | Unspecified vulnerability in Atlassian Jira Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability. | 4.9 |