Skip to content
VulniPulse

Atlassian Security Advisories & CVEs

89 advisories tracked · Atlassian (security@atlassian.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Atlassian CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Atlassian device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Atlassian's recent advisories.

Official source

Atlassian (security@atlassian.com CNA) via NVD

Atlassian is its own CVE Numbering Authority. VulniPulse ingests Atlassian's CVEs from the NVD CNA feed (security@atlassian.com), each linking to its security advisory / Jira ticket. Covers Confluence (Server & Data Center), Jira (Software & Service Management), Bitbucket, Bamboo, Crowd and Fisheye/Crucible — self-hosted Confluence/Jira are repeatedly hit by mass-exploited RCE and auth-bypass bugs (CVE-2023-22515, CVE-2022-26134), so a huge patch-now audience.

Latest Atlassian advisories

Medium4.3Atlassian

Medium [CVE-2022-36800] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.

CVE-2022-36800
Jira
Aug 3, 2022
Medium5.7Atlassian

Medium [CVE-2021-43959] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this flaw may be used to access to a metadata resource that provides access credentials and other potentially confidential information. The affected versions are before version 4.13.20, from version 4.14.0 before 4.20.8, and from version 4.21.0 before 4.22.2.

CVE-2021-43959
Jira
Jul 26, 2022
Medium5.4Atlassian

Medium [CVE-2020-36290] The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from…

The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.

CVE-2020-36290
Confluence
Jul 26, 2022
Medium6.5Atlassian

Medium [CVE-2022-26135] vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4.

CVE-2022-26135
Jira
Jun 30, 2022
Medium6.1Atlassian

Medium [CVE-2021-43956] The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML…

The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.

CVE-2021-43956
Bamboo / Crowd / Fisheye
Mar 16, 2022
Medium4.3Atlassian

Medium [CVE-2021-43955] The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers…

The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.

CVE-2021-43955
Bamboo / Crowd / Fisheye
Mar 16, 2022
Medium4.3Atlassian

Medium [CVE-2021-43954] The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add…

The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.

CVE-2021-43954
Bamboo / Crowd / Fisheye
Mar 14, 2022
Medium4.8Atlassian

Medium [CVE-2021-43945] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.

CVE-2021-43945
Jira
Feb 28, 2022
Medium4.8Atlassian

Medium [CVE-2021-43943] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are before version 4.21.0.

CVE-2021-43943
Jira
Feb 24, 2022
Medium4.3Atlassian

Medium [CVE-2021-43948] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.

CVE-2021-43948
Jira
Feb 15, 2022
Medium6.5Atlassian

Medium [CVE-2021-43941] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43941
Jira
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43953] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.20.5.

CVE-2021-43953
Jira
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43950] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.

CVE-2021-43950
Jira
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43952] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.

CVE-2021-43952
Jira
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43951] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0.

CVE-2021-43951
Jira
Jan 10, 2022
Medium4.3Atlassian

Medium [CVE-2021-43949] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.

CVE-2021-43949
Jira
Jan 10, 2022
Medium6.5Atlassian

Medium [CVE-2021-43946] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.13.21, and from version 8.14.0 before 8.20.9.

CVE-2021-43946
Jira
Jan 5, 2022
Medium6.1Atlassian

Medium [CVE-2021-43942] Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. To exploit this issue, the attacker must trick a user into visiting a malicious website. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43942
Jira
Jan 4, 2022
Medium5.3Atlassian

Medium [CVE-2021-41309] Jira Service Management: Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the /plugins/servlet/audit/resource endpoint.

CVE-2021-41309
Jira
Dec 8, 2021
Medium6.1Atlassian

Medium [CVE-2021-41310] Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11, and from version 8.14.0 before 8.19.1.

CVE-2021-41310
Jira
Nov 1, 2021

← All vendors