Jira
Vendor:
First CVE: Jul 3, 2006 · Active for 20 years
155
Total CVEs
More Total CVEs than 99% of tracked products
11.9
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jira over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2006
20 years ago
Most Recent CVE
Feb 28, 2022
1,611 days ago
CVE Severity & Scoring
Jira155 CVEs
83%
13%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network141 (91.0%)
Unknown14 (9.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low136 (87.7%)
High5 (3.2%)
Unknown14 (9.0%)
User Interaction
None74 (47.7%)
Unknown14 (9.0%)
Required67 (43.2%)
Privileges Required
Low31 (20.0%)
High12 (7.7%)
None98 (63.2%)
Unknown14 (9.0%)
Top CVEs
Signals from CVEs in this product scope (155 CVEs).
155 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14181MEDIUM Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa e | Sep 17, 2020 | 5.3 | 88 | NO | YES |
CVE-2012-2926CRITICAL Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo b | May 22, 2012 | 9.1 | 82 | NO | YES |
CVE-2020-36289MEDIUM Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendere | May 12, 2021 | 5.3 | 80 | NO | YES |
CVE-2019-8451MEDIUM The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request | Sep 11, 2019 | 6.5 | 78 | NO | YES |
CVE-2019-8449MEDIUM The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability. | Sep 11, 2019 | 5.3 | 77 | NO | YES |
CVE-2019-8442HIGH The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote a | May 22, 2019 | 7.5 | 68 | NO | YES |
CVE-2019-3403MEDIUM The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attacker | May 22, 2019 | 5.3 | 58 | NO | YES |
CVE-2018-20824MEDIUM The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyc | May 3, 2019 | 6.1 | 53 | NO | YES |
CVE-2017-5983CRITICAL The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, rea | Apr 10, 2017 | 9.8 | 52 | NO | YES |
CVE-2018-5230MEDIUM The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7 | May 14, 2018 | 6.1 | 51 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (155 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
1.9% of CVEs· 97th percentile
Nuclei
12 CVEs
7.7% of CVEs· 97th percentile
ExploitDB
6 CVEs
3.9% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (155 CVEs).
Media Mentions
Signals from CVEs in this product scope (155 CVEs).
Top CNAs Publishing CVEs For Jira
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8 | 1 | 5.3 | 1.4% | 0 | 0 |
| 6.2.7 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.2.6 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.2.5 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.2.4 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.2.3 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.2.2 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.2.1 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.2 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1.9 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1.8 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1.7 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1.6 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1.5 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1.4 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1.3 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1.2 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1.1 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.1 | 1 | 9.8 | 16.2% | 0 | 1 |
| 6.0.8 | 1 | 9.8 | 16.2% | 0 | 1 |