📦 Jira Server

by Atlassian

🔍 What is Jira Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-26136

CRITICAL CVSS 9.8 Jul 20, 2022

This vulnerability allows remote unauthenticated attackers to bypass Servlet Filters in multiple Atlassian products, potentially leading to authentication bypass and cross-site scripting attacks. Orga...

CVE-2024-21683

HIGH CVSS 8.8 May 21, 2024

This is a high-severity remote code execution vulnerability in Confluence Data Center and Server that allows authenticated attackers to execute arbitrary code on affected systems. It affects Confluenc...

CVE-2021-43944

HIGH CVSS 7.2 Mar 8, 2022

This vulnerability allows remote attackers with system administrator permissions in Atlassian Jira Server and Data Center to execute arbitrary code via template injection in the Email Templates featur...

CVE-2021-43947

HIGH CVSS 7.2 Jan 6, 2022

This vulnerability allows remote attackers with administrator privileges in Atlassian Jira Server and Data Center to execute arbitrary code via the Email Templates feature. It affects versions before ...

CVE-2021-41307

HIGH CVSS 7.5 Oct 26, 2021

This vulnerability allows unauthenticated remote attackers to view names of private projects and filters in Atlassian Jira Server and Data Center via an Insecure Direct Object Reference (IDOR) in the ...

CVE-2021-39113

HIGH CVSS 7.5 Aug 30, 2021

This vulnerability allows anonymous remote attackers to view cached content in Atlassian Jira Server and Data Center even after losing proper permissions. It affects organizations running vulnerable v...

CVE-2021-26070

HIGH CVSS 7.2 Mar 22, 2021

This Broken Authentication vulnerability in Atlassian Jira allows remote attackers to bypass firewall protections for app-linked resources via the makeRequest gadget. Attackers can access internal res...

CVE-2019-15002

MEDIUM CVSS 4.3 Feb 11, 2025

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira, where the login form lacks a CSRF token, allowing attackers to trick users into logging into an attacker-control...