Skip to content
VulniPulse

Atlassian Security Advisories & CVEs

166 advisories tracked · Atlassian (security@atlassian.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Atlassian CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Atlassian device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Atlassian's recent advisories.

Official source

Atlassian (security@atlassian.com CNA) via NVD

Atlassian is its own CVE Numbering Authority. VulniPulse ingests Atlassian's CVEs from the NVD CNA feed (security@atlassian.com), each linking to its security advisory / Jira ticket. Covers Confluence (Server & Data Center), Jira (Software & Service Management), Bitbucket, Bamboo, Crowd and Fisheye/Crucible — self-hosted Confluence/Jira are repeatedly hit by mass-exploited RCE and auth-bypass bugs (CVE-2023-22515, CVE-2022-26134), so a huge patch-now audience.

Latest Atlassian advisories

Medium4.3Atlassian

Medium [CVE-2021-43954] The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add…

The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.

CVE-2021-43954
Bamboo / Crowd / Fisheye
Mar 14, 2022
High7.2Atlassian

High [CVE-2021-43944] This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been…

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43944
Jira
Mar 8, 2022
Medium4.8Atlassian

Medium [CVE-2021-43945] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.

CVE-2021-43945
Jira
Feb 28, 2022
Medium4.8Atlassian

Medium [CVE-2021-43943] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are before version 4.21.0.

CVE-2021-43943
Jira
Feb 24, 2022
High7.8Atlassian

High [CVE-2021-43940] Affected versions of Atlassian Confluence Server and Data Center

Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CVE-2021-43940
Confluence
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43948] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.

CVE-2021-43948
Jira
Feb 15, 2022
Medium6.5Atlassian

Medium [CVE-2021-43941] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43941
Jira
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43953] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.20.5.

CVE-2021-43953
Jira
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43950] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.

CVE-2021-43950
Jira
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43952] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.

CVE-2021-43952
Jira
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43951] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0.

CVE-2021-43951
Jira
Jan 10, 2022
Medium4.3Atlassian

Medium [CVE-2021-43949] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.

CVE-2021-43949
Jira
Jan 10, 2022
High7.2Atlassian

High [CVE-2021-43947] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43947
Jira
Jan 6, 2022
Medium6.5Atlassian

Medium [CVE-2021-43946] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.13.21, and from version 8.14.0 before 8.20.9.

CVE-2021-43946
Jira
Jan 5, 2022
Medium6.1Atlassian

Medium [CVE-2021-43942] Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. To exploit this issue, the attacker must trick a user into visiting a malicious website. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43942
Jira
Jan 4, 2022
High7.5Atlassian

High [CVE-2021-41311] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.

CVE-2021-41311
Jira
Dec 8, 2021
Medium5.3Atlassian

Medium [CVE-2021-41309] Jira Service Management: Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the /plugins/servlet/audit/resource endpoint.

CVE-2021-41309
Jira
Dec 8, 2021
High7.5Atlassian

High [CVE-2021-41312] Jira Service Management: Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.

CVE-2021-41312
Jira
Nov 3, 2021
Medium6.1Atlassian

Medium [CVE-2021-41310] Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11, and from version 8.14.0 before 8.19.1.

CVE-2021-41310
Jira
Nov 1, 2021
Medium4.3Atlassian

Medium [CVE-2021-41313] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are before version 8.20.7.

CVE-2021-41313
Jira
Nov 1, 2021

← All vendors