Jira Software Data Center

Vendor:

First CVE: Feb 6, 2020 · Active for 6 years

39
Total CVEs
More Total CVEs than 98% of tracked products
19.5
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jira Software Data Center over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2020
6 years ago
Most Recent CVE
Dec 8, 2021
1,692 days ago

CVE Severity & Scoring

Jira Software Data Center39 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network39 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None27 (69.2%)
Unknown0 (0.0%)
Required12 (30.8%)
Privileges Required
Low12 (30.8%)
High3 (7.7%)
None24 (61.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templat
Jul 3, 20209.831NONO
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were ab
Jun 23, 20209.831NONO
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPi
Jun 29, 20207.526NONO
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The
Jul 13, 20207.525NONO
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles
Dec 8, 20217.524NONO
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct O
Oct 26, 20217.524NONO
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR)
Oct 26, 20217.524NONO
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object Referenc
Oct 26, 20217.524NONO
The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected ve
Jul 13, 20206.523NONO
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in
Jul 3, 20206.523NONO

Exploit Exposure

Signals from CVEs in this product scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (39 CVEs).

Media Mentions

Signals from CVEs in this product scope (39 CVEs).

Top CNAs Publishing CVEs For Jira Software Data Center

Top CWEs

Versions

No cataloged versions.