Atlassian Jira Server 8.13.22

CPE Details

Atlassian Jira Server 8.13.22
8.13.22
2022-07-12
08h35 +00:00
2022-07-20
16h40 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:atlassian:jira_server:8.13.22:*:*:*:*:*:*:*

Informations

Vendor

atlassian

Product

jira_server

Version

8.13.22

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-36801 2022-08-10 02h20 +00:00 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8.
6.1
Moyen
CVE-2021-41313 2021-11-01 03h05 +00:00 Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are before version 8.20.7.
4.3
Moyen
CVE-2020-36232 2021-02-22 20h46 +00:00 The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.
5
Moyen