Skip to content
VulniPulse

Atlassian Security Advisories & CVEs

89 advisories tracked · Atlassian (security@atlassian.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Atlassian CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Atlassian device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Atlassian's recent advisories.

Official source

Atlassian (security@atlassian.com CNA) via NVD

Atlassian is its own CVE Numbering Authority. VulniPulse ingests Atlassian's CVEs from the NVD CNA feed (security@atlassian.com), each linking to its security advisory / Jira ticket. Covers Confluence (Server & Data Center), Jira (Software & Service Management), Bitbucket, Bamboo, Crowd and Fisheye/Crucible — self-hosted Confluence/Jira are repeatedly hit by mass-exploited RCE and auth-bypass bugs (CVE-2023-22515, CVE-2022-26134), so a huge patch-now audience.

Latest Atlassian advisories

Medium4.3Atlassian

Medium [CVE-2025-22178] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.

CVE-2025-22178
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22177] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.

CVE-2025-22177
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22176] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.

CVE-2025-22176
Jira
Oct 22, 2025
Medium5.4Atlassian

Medium [CVE-2025-22175] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.

CVE-2025-22175
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22174] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

CVE-2025-22174
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22173] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.

CVE-2025-22173
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22172] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.

CVE-2025-22172
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22171] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.

CVE-2025-22171
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22170] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.

CVE-2025-22170
Jira
Oct 22, 2025
Medium5.4Atlassian

Medium [CVE-2025-22169] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.

CVE-2025-22169
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22168] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.

CVE-2025-22168
Jira
Oct 22, 2025
Medium6.5Atlassian

Medium [CVE-2025-22167] Jira Software: This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present…

This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by the Jira JVM process. Atlassian recommends that Jira Software Data Center and Server customers upgrade to the latest version; if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Jira Software Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.28 See the release notes. This vulnerability was reported via our Atlassian (Internal) program.

CVE-2025-22167
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2019-15002] Jira: exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0.

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.

CVE-2019-15002
Jira
Feb 11, 2025
Medium6.4Atlassian

Medium [CVE-2024-21703] This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and…

This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about the Confluence Data Center configuration which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to the latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: - Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.18 See the release notes ( ). This vulnerability was reported via our Atlassian Bug Bounty Program by Chris Elliot.

CVE-2024-21703
Confluence
Nov 27, 2024
Medium4.3Atlassian

Medium [CVE-2024-21684] Bitbucket: There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center.

There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability, with a CVSS Score of 3.1 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N, allows an unauthenticated attacker to redirect a victim user upon login to Bitbucket Data Center to any arbitrary site which can be utilized for further exploitation which has low impact to confidentiality, no impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Bitbucket Data Center customers upgrade to the version. If you are unable to do so, upgrade your instance to one of the supported fixed versions.

CVE-2024-21684
Bitbucket
Jul 24, 2024
Medium6.5Atlassian

Medium [CVE-2024-21685] This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data…

This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Information Disclosure vulnerability, with a CVSS Score of 7.4, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability which has high impact to confidentiality, no impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Jira Core Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21 See the release notes. This vulnerability was found internally.

CVE-2024-21685
Jira
Jun 18, 2024
Medium6.5Atlassian

Medium [CVE-2023-22504] Affected versions of Atlassian Confluence Server

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

CVE-2023-22504
Confluence
May 25, 2023
Medium5.3Atlassian

Medium [CVE-2023-22503] Affected versions of Atlassian Confluence Server and Data Center

Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team. The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.

CVE-2023-22503
Confluence
May 1, 2023
Medium4.9Atlassian

Medium [CVE-2022-36802] The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2

The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP request.

CVE-2022-36802
Jira
Oct 14, 2022
Medium6.1Atlassian

Medium [CVE-2022-36801] Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8.

CVE-2022-36801
Jira
Aug 10, 2022

← All vendors