Vulnerabilities (CVE)

Filtered by vendor Atlassian Subscribe
Filtered by product Jira
Total 143 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-6617 1 Atlassian 1 Jira 2008-11-15 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 allows remote attackers to inject arbitrary web script or HTML, which is not properly handled when generating error messages, as demonstrated by input originally sent in the URI to secure/CreateIssue. NOTE: some of these details are obtained from third party information.
CVE-2007-6618 1 Atlassian 1 Jira 2008-11-15 5.0 MEDIUM N/A
JIRA Enterprise Edition before 3.12.1 allows remote attackers to delete another user's shared filter via a modified filter ID.
CVE-2007-6619 1 Atlassian 1 Jira 2008-11-15 7.5 HIGH N/A
The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows remote attackers to change the default language.