Atlassian
atlassian
466 CVEs • 59 products
Products (59)
Click to collapseToggle
Products (59)
Click to collapse
CVEs (466)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Atlassian 1Connect Spring Boot Feb 12, 2025 Apr 16, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication betwe...Show more |
Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian produ...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreNov 21, 2024 Apr 15, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote a...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreNov 21, 2024 Apr 15, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attac...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreNov 21, 2024 Apr 15, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitra...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreNov 21, 2024 Apr 9, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to...Show more |
1Atlassian 2Confluence Data Center Confluence ServerNov 21, 2024 Apr 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SS...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreNov 21, 2024 Apr 1, 2021 N/A· v4 3.5 LOW· v3 3.5 LOW· v2 The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enabl...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreNov 21, 2024 Apr 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determi...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreNov 21, 2024 Apr 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determi...Show more |
1Atlassian 3Data Center JiraJira ServerNov 21, 2024 Mar 22, 2021 N/A· v4 7.2 HIGH· v3 6.4 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget reso...Show more |
1Atlassian 4Data Center JiraJira Data Center+1 moreNov 21, 2024 Mar 22, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/is...Show more |
The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an inc...Show more |
1Atlassian 1Jira Server For Slack Nov 21, 2024 Feb 22, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability. |
1Atlassian 1Atlassian Gadgets Nov 21, 2024 Feb 22, 2021 N/A· v4 5.0 MEDIUM· v3 4.0 MEDIUM· v2 The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 al...Show more |
1Atlassian 3Data Center Jira Data CenterJira ServerNov 21, 2024 Feb 22, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary f...Show more |
1Atlassian 2Confluence Data Center Confluence ServerNov 21, 2024 Feb 22, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to re...Show more |
1Atlassian 1Alfresco Enterprise Content Management Nov 21, 2024 Feb 19, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system comma...Show more |
The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak p...Show more |
1Atlassian 3Data Center JiraJira ServerNov 21, 2024 Feb 15, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are...Show more |