Jira Software Data Center
Vendor:
First CVE: Feb 6, 2020 · Active for 6 years
39
Total CVEs
More Total CVEs than 98% of tracked products
19.5
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jira Software Data Center over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2020
6 years ago
Most Recent CVE
Dec 8, 2021
1,692 days ago
CVE Severity & Scoring
Jira Software Data Center39 CVEs
74%
21%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network39 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None27 (69.2%)
Unknown0 (0.0%)
Required12 (30.8%)
Privileges Required
Low12 (30.8%)
High3 (7.7%)
None24 (61.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14172CRITICAL This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templat | Jul 3, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-20409CRITICAL The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were ab | Jun 23, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-20413HIGH Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPi | Jun 29, 2020 | 7.5 | 26 | NO | NO |
CVE-2019-20898HIGH Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The | Jul 13, 2020 | 7.5 | 25 | NO | NO |
CVE-2021-41311HIGH Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles | Dec 8, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-41307HIGH Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct O | Oct 26, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-41306HIGH Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) | Oct 26, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-41305HIGH Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object Referenc | Oct 26, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-20897MEDIUM The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected ve | Jul 13, 2020 | 6.5 | 23 | NO | NO |
CVE-2019-20418MEDIUM Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in | Jul 3, 2020 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (39 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (39 CVEs).
Media Mentions
Signals from CVEs in this product scope (39 CVEs).
Top CNAs Publishing CVEs For Jira Software Data Center
Top CWEs
Versions
No cataloged versions.