Jira

Vendor:

First CVE: Jul 3, 2006 · Active for 20 years

155
Total CVEs
More Total CVEs than 99% of tracked products
11.9
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jira over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2006
20 years ago
Most Recent CVE
Feb 28, 2022
1,611 days ago

CVE Severity & Scoring

Jira155 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network141 (91.0%)
Unknown14 (9.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low136 (87.7%)
High5 (3.2%)
Unknown14 (9.0%)
User Interaction
None74 (47.7%)
Unknown14 (9.0%)
Required67 (43.2%)
Privileges Required
Low31 (20.0%)
High12 (7.7%)
None98 (63.2%)
Unknown14 (9.0%)

Top CVEs

Signals from CVEs in this product scope (155 CVEs).

155 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa e
Sep 17, 20205.388NOYES
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo b
May 22, 20129.182NOYES
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendere
May 12, 20215.380NOYES
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request
Sep 11, 20196.578NOYES
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
Sep 11, 20195.377NOYES
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote a
May 22, 20197.568NOYES
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attacker
May 22, 20195.358NOYES
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyc
May 3, 20196.153NOYES
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, rea
Apr 10, 20179.852NOYES
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7
May 14, 20186.151NOYES

Exploit Exposure

Signals from CVEs in this product scope (155 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
1.9% of CVEs· 97th percentile
Nuclei
12 CVEs
7.7% of CVEs· 97th percentile
ExploitDB
6 CVEs
3.9% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (155 CVEs).

Media Mentions

Signals from CVEs in this product scope (155 CVEs).

Top CNAs Publishing CVEs For Jira

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
815.31.4%00
6.2.719.816.2%01
6.2.619.816.2%01
6.2.519.816.2%01
6.2.419.816.2%01
6.2.319.816.2%01
6.2.219.816.2%01
6.2.119.816.2%01
6.219.816.2%01
6.1.919.816.2%01
6.1.819.816.2%01
6.1.719.816.2%01
6.1.619.816.2%01
6.1.519.816.2%01
6.1.419.816.2%01
6.1.319.816.2%01
6.1.219.816.2%01
6.1.119.816.2%01
6.119.816.2%01
6.0.819.816.2%01