Atlassian Data Center 8.18.2

CPE Details

Atlassian Data Center 8.18.2
8.18.2
2021-08-30
14h06 +00:00
2022-03-30
11h29 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:atlassian:data_center:8.18.2:*:*:*:*:*:*:*

Informations

Vendor

atlassian

Product

data_center

Version

8.18.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-43945 2022-02-28 00h20 +00:00 Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
4.8
Medium
CVE-2021-43953 2022-02-15 02h40 +00:00 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.20.5.
4.3
Medium
CVE-2021-41312 2021-11-03 03h50 +00:00 Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.
7.5
High
CVE-2021-39118 2021-09-14 04h55 +00:00 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0.
5.3
Medium
CVE-2021-39119 2021-09-01 22h50 +00:00 Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected versions are before version 8.19.0.
5.3
Medium