![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39118
https://notcve.org/view.php?id=CVE-2021-39118
14 Sep 2021 — Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0. Unas versiones afectadas de Atlassian Jira Server y Data Center permiten a atacantes remotos detectar los nombres de usuario y los nombres completos de los usuarios por medio de una vulnerabilidad de enumeración en el endpoint /rest/api/1.0/render. Las version... • https://jira.atlassian.com/browse/JRASERVER-72736 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39123
https://notcve.org/view.php?id=CVE-2021-39123
14 Sep 2021 — Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint. The affected versions are before version 8.16.0. Unas versiones afectadas de Atlassian Jira Server y Data Center permiten a atacantes no autenticados remotos impactar en la disponibilidad de la aplicación por medio de una vulnerabilidad de Denegación de Servicio (DoS)... • https://jira.atlassian.com/browse/JRASERVER-72237 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39124
https://notcve.org/view.php?id=CVE-2021-39124
14 Sep 2021 — The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request. La funcionalidad de tipo Cross-Site Request Forgery (CSRF) failure retry de Atlassian Jira Server y Data Center versiones anteriores a 8.16.0, permite a atacantes remotos que son capaces de engañar a un usuario para que reintente una petición para omitir l... • https://jira.atlassian.com/browse/JRASERVER-72761 • CWE-352: Cross-Site Request Forgery (CSRF) •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39122
https://notcve.org/view.php?id=CVE-2021-39122
08 Sep 2021 — Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1. Las versiones afectadas de Atlassian Jira Server y Data Center permiten a atacantes remotos anónimos visualizar los correos electrónicos de los usuarios por medio de una vulnerabilidad de divulgac... • https://jira.atlassian.com/browse/JRASERVER-72293 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39121
https://notcve.org/view.php?id=CVE-2021-39121
08 Sep 2021 — Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before version 8.5.18, from version 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2. Las versiones afectadas de Atlassian Jira Server y Data Center permiten a atacantes remotos autenticados enumerar las claves de los proyectos privad... • https://jira.atlassian.com/browse/JRASERVER-72715 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39116
https://notcve.org/view.php?id=CVE-2021-39116
08 Sep 2021 — Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the GIF Image Reader component. The affected versions are before version 8.13.14, and from version 8.14.0 before 8.19.0. Las versiones afectadas de Atlassian Jira Server y Data Center permiten a los atacantes remotos impactar en la disponibilidad de la aplicación a través de una vulnerabilidad de denegación de servicio (DoS) en el component... • https://jira.atlassian.com/browse/JRASERVER-72738 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39115
https://notcve.org/view.php?id=CVE-2021-39115
01 Sep 2021 — Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0. Las versiones afectadas de Atlassian Jira Service Management Server y Data Center permiten a atacantes remotos con acceso "Jira Administrators"... • https://github.com/PetrusViet/CVE-2021-39115 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-96: Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39119
https://notcve.org/view.php?id=CVE-2021-39119
01 Sep 2021 — Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected versions are before version 8.19.0. Las versiones afectadas de Atlassian Jira Server y Data Center permiten a usuarios que han observado un problema sigan recibiendo actualizaciones sobre la misma incluso después de que su cuenta de Jira se... • https://jira.atlassian.com/browse/JRASERVER-72737 • CWE-863: Incorrect Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39117
https://notcve.org/view.php?id=CVE-2021-39117
30 Aug 2021 — The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field. La página AssociateFieldToScreens en Atlassian Jira Server y Data Center versiones anteriores a 8.18.0, permite a atacantes remotos inyectar HTML o JavaScript arbitrario por medio de una vulnerabilidad de tipo Cross-Site Scripting (XSS) por medio del nombre de un campo pers... • https://jira.atlassian.com/browse/JRASERVER-72597 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-39113
https://notcve.org/view.php?id=CVE-2021-39113
30 Aug 2021 — Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0. Unas versiones afectadas de Atlassian Jira Server y Data Center permiten a atacantes remotos anónimos seguir visualizando el contenido en caché incluso después de perder los permisos, por medio de u... • https://jira.atlassian.com/browse/JRASERVER-72573 • CWE-613: Insufficient Session Expiration •