<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Jira Software</title>
  <link>https://cvedaily.com/pages/tags/jira-software.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/jira-software.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Jira Software</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2025-22167 – This High severity Path Traversal (Arbitrary Write) vulnerability was introduced...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22167</guid>
    <pubDate>Wed, 22 Oct 2025 01:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22167</strong></p>
  <p>This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by the Jira JVM process. Atlassian recommends that Jira Software Data Center and Se…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-36239 – Jira Data Center, Jira Core Data Center, Jira Software Data Center from version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36239</guid>
    <pubDate>Thu, 29 Jul 2021 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-36239</strong></p>
  <p>Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-26071 – The SetFeatureEnabled.jspa resource in Jira Server and Data Center before versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26071</guid>
    <pubDate>Thu, 01 Apr 2021 03:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-26071</strong></p>
  <p>The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-20407 – The ConfigureBambooRelease resource in Jira Software and Jira Software Data Cent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20407</guid>
    <pubDate>Tue, 17 Mar 2020 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-20407</strong></p>
  <p>The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-8481 – Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Des...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8481</guid>
    <pubDate>Fri, 08 Jan 2016 19:59:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-8481</strong></p>
  <p>Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote attackers to obtain sensitive information by updating a different issue that includes wiki markup for an external image reference.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8481">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
