CVE-2025-22167
This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal…
All CVEs associated with "Jira Software". Page 1/1 • 5 CVEs.
A curated feed of “Jira Software”-related CVEs appears below. We currently track 5 CVEs for this tag (all time). In the last 365 days, 1 were published. Average CVSS is 5.4 (all time; 6.5 over 365d), and 20% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').
In our taxonomy this topic maps to a LOW impact class. Atlassian apps hold code and project data. Patch, enforce SSO or MFA, restrict anonymous access, and audit marketplace apps and macros. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | EOL | LTS |
|---|---|---|---|---|
| 11.3 | 11.3.6 | LTS | ||
| 11.2 | 11.2.1 | |||
| 11.1 | 11.1.1 | |||
| 11.0 | 11.0.1 | |||
| 10.7 | 10.7.4 | |||
| 10.6 | 10.6.1 | |||
| 10.5 | 10.5.1 | |||
| 10.4 | 10.4.1 | |||
| 10.3 | 10.3.22 | LTS | ||
| 10.2 | 10.2.1 | Soon | ||
| 10.1 | 10.1.2 | Soon | ||
| 10.0 | 10.0.1 | Soon | ||
| 9.17 | 9.17.5 | Soon | ||
| 9.16 | 9.16.1 | Expired | ||
| 9.15 | 9.15.2 | Expired | ||
| 9.14 | 9.14.1 | Expired | ||
| 9.13 | 9.13.1 | Expired | ||
| 9.12 | 9.12.35 | Expired | LTS | |
| 9.11 | 9.11.3 | Expired | ||
| 9.10 | 9.10.2 | Expired | ||
| 9.9 | 9.9.2 | Expired | ||
| 9.8 | 9.8.2 | Expired | ||
| 9.7 | 9.7.2 | Expired | ||
| 9.6 | 9.6.0 | Expired | ||
| 9.5 | 9.5.1 | Expired | ||
| 9.4 | 9.4.30 | Expired | LTS | |
| 9.3 | 9.3.3 | Expired | ||
| 9.2 | 9.2.1 | Expired | ||
| 9.1 | 9.1.1 | Expired | ||
| 9.0 | 9.0.0 | Expired | ||
| 8.22 | 8.22.6 | Expired | ||
| 8.21 | 8.21.1 | Expired | ||
| 8.20 | 8.20.30 | Expired | LTS | |
| 8.19 | 8.19.1 | Expired | ||
| 8.18 | 8.18.2 | Expired | ||
| 8.17 | 8.17.1 | Expired | ||
| 8.16 | 8.16.2 | Expired | ||
| 8.15 | 8.15.1 | Expired | ||
| 8.14 | 8.14.1 | Expired | ||
| 8.13 | 8.13.27 | Expired | LTS | |
| 8.12 | 8.12.3 | Expired | ||
| 8.11 | 8.11.1 | Expired | ||
| 8.10 | 8.10.1 | Expired | ||
| 8.9 | 8.9.1 | Expired | ||
| 8.8 | 8.8.1 | Expired | ||
| 8.7 | 8.7.1 | Expired | ||
| 8.6 | 8.6.1 | Expired | ||
| 8.5 | 8.5.19 | Expired | LTS | |
| 8.4 | 8.4.3 | Expired | ||
| 8.3 | 8.3.5 | Expired | ||
| 8.2 | 8.2.6 | Expired | ||
| 8.1 | 8.1.3 | Expired | ||
| 8.0 | 8.0.3 | Expired | ||
| 7.13 | 7.13.18 | Expired | LTS | |
| 7.12 | 7.12.3 | Expired | ||
| 7.11 | 7.11.2 | Expired | ||
| 7.10 | 7.10.2 | Expired | ||
| 7.9 | 7.9.2 | Expired | ||
| 7.8 | 7.8.4 | Expired | ||
| 7.7 | 7.7.4 | Expired | ||
| 7.6 | 7.6.17 | Expired | LTS | |
| 7.5 | 7.5.4 | Expired | ||
| 7.4 | 7.4.6 | Expired | ||
| 7.3 | 7.3.9 | Expired | ||
| 7.2 | 7.2.15 | Expired | ||
| 7.1 | 7.1.10 | Expired | ||
| 7.0 | 7.0.11 | Expired | ||
| 6.4 | 6.4.14 | Expired | ||
| 6.3 | 6.3.15 | Expired | ||
| 6.2 | 6.2.7 | Expired | ||
| 6.1 | 6.1.9 | Expired | ||
| 6.0 | 6.0.8 | Expired | ||
| 5.2 | 5.2.11 | - Expired | ||
| 5.1 | 5.1.8 | - Expired | ||
| 5.0 | 5.0.7 | Expired | ||
| 4.4 | 4.4.5 | Expired | ||
| 4.3 | 4.3.4 | Expired | ||
| 4.2 | 4.2.4 | Expired | ||
| 4.1 | 4.1.2 | Expired | ||
| 4.0 | 4.0.2 | Expired | ||
| 3.13 | 3.13.5 | Expired | ||
| 3.12 | 3.12.3 | - Expired | ||
| 3.11 | 3.11.0 | - Expired | ||
| 3.10 | 3.10.2 | - Expired | ||
| 3.9 | 3.9.3 | - Expired | ||
| 3.8 | 3.8.1 | - Expired | ||
| 3.7 | 3.7.4 | - Expired | ||
| 3.6 | 3.6.5 | - Expired | ||
| 3.5 | 3.5.3 | - Expired | ||
| 3.4 | 3.4.3 | - Expired | ||
| 3.3 | 3.3.3 | - Expired | ||
| 3.2 | 3.2.3 | - Expired | ||
| 3.1 | 3.1.1 | - Expired | ||
| 3.0 | 3.0.3 | - Expired | ||
| 2.6 | 2.6.1 | - Expired | ||
| 2.5 | 2.5.3 | - Expired | ||
| 2.4 | 2.4.0 | - Expired | ||
| 2.3 | 2.3.0 | - Expired | ||
| 2.2 | 2.2.1 | - Expired | ||
| 2.1 | 2.1.0 | - Expired | ||
| 1.4 | 1.4.1 | - Expired | ||
| 1.3 | 1.3.3 | - Expired | ||
| 1.2 | 1.2.0 | - Expired | ||
| 1.1 | 1.1.0 | - Expired | ||
| 1.0 | 1.0.0 | - Expired |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Jira Software” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal…
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from v…
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymo…
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they…
Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup r…