Atlassian
Atlassian Jira Server: vulnerabilidades y CVE
Atlassian Jira Server tiene 135 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE135
Últimos 12 meses1
Críticas3
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-26086 | Media (5.3) | 100% | ⚠ Explotación activa | 16 ago 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version… |
| CVE-2019-11581 | Crítica (9.8) | 85% | ⚠ Explotación activa | 9 ago 2019 | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-22167 | Alta (8.7) | 0.50% | — | 22 oct 2025 | This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write)… |
| CVE-2025-22157 | Alta (7.2) | 0.69% | — | 20 may 2025 | This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service… |
| CVE-2019-15002 | Media (4.3) | 0.32% | — | 11 feb 2025 | An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account. |
| CVE-2024-21685 | Media (6.5) | 0.44% | — | 18 jun 2024 | This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21 Jira… |
| CVE-2024-21683 | Alta (8.8) | 88% | — | 21 may 2024 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an… |
| CVE-2022-36801 | Media (6.1) | 66% | — | 10 ago 2022 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa… |
| CVE-2022-36799 | Alta (7.2) | 45% | — | 1 ago 2022 | This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote… |
| CVE-2022-26137 | Alta (8.8) | 2.3% | — | 20 jul 2022 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed… |
| CVE-2022-26136 | Crítica (9.8) | 5.4% | — | 20 jul 2022 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how… |
| CVE-2022-26135 | Media (6.5) | 72% | — | 30 jun 2022 | A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch… |
| CVE-2022-0540 | Crítica (9.8) | 88% | — | 20 abr 2022 | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18,… |
| CVE-2021-43944 | Alta (7.2) | 2.3% | — | 8 mar 2022 | This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote… |
| CVE-2021-43941 | Media (6.5) | 0.62% | — | 15 feb 2022 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery… |
| CVE-2021-43952 | Media (4.3) | 0.41% | — | 15 feb 2022 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the… |
| CVE-2021-43947 | Alta (7.2) | 4.1% | — | 6 ene 2022 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature.… |
| CVE-2021-43946 | Media (6.5) | 1.1% | — | 5 ene 2022 | Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the… |
| CVE-2021-43942 | Media (6.1) | 55% | — | 4 ene 2022 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the… |
| CVE-2021-41313 | Media (4.3) | 0.87% | — | 1 nov 2021 | Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the… |
| CVE-2021-41308 | Media (6.5) | 1.0% | — | 26 oct 2021 | Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the… |
| CVE-2021-41307 | Alta (7.5) | 1.7% | — | 26 oct 2021 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability… |
| CVE-2021-41306 | Alta (7.5) | 1.6% | — | 26 oct 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in… |
| CVE-2021-41304 | Media (6.1) | 0.88% | — | 26 oct 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the… |
| CVE-2021-39127 | Media (5.3) | 1.3% | — | 21 oct 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are… |
| CVE-2021-39126 | Media (6.5) | 0.73% | — | 21 oct 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in… |
| CVE-2021-39128 | Alta (7.2) | 1.9% | — | 16 sept 2021 | Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-side template… |
| CVE-2021-39125 | Media (5.3) | 1.4% | — | 14 sept 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are… |
| CVE-2021-39122 | Media (5.3) | 1.4% | — | 8 sept 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are… |
| CVE-2021-39121 | Media (4.3) | 1.1% | — | 8 sept 2021 | Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the… |
| CVE-2021-39116 | Media (5.5) | 1.1% | — | 8 sept 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the GIF Image Reader component. The affected… |
| CVE-2021-39113 | Alta (7.5) | 2.5% | — | 30 ago 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.