Atlassian
atlassian
466 CVEs • 59 products
Products (59)
Click to collapseToggle
Products (59)
Click to collapse
CVEs (466)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Atlassian 1Jira Service Desk Nov 21, 2024 Sep 21, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulne...Show more |
1Atlassian 2Jira Data Center Jira ServerNov 21, 2024 Sep 21, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent...Show more |
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected ve...Show more |
1Atlassian 3Data Center JiraJira ServerNov 21, 2024 Sep 17, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are befor...Show more |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreNov 21, 2024 Sep 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before...Show more |
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3. |
1Atlassian 2Confluence Data Center Confluence ServerNov 21, 2024 Jul 24, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected version...Show more |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreNov 21, 2024 Jul 13, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper....Show more |
The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack...Show more |
1Atlassian 2Jira Data Center Jira ServerNov 21, 2024 Jul 13, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the Add Field module. The affected versions are b...Show more |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreNov 21, 2024 Jul 13, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are befo...Show more |
1Atlassian 2Jira Jira Software Data CenterNov 21, 2024 Jul 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8...Show more |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreNov 21, 2024 Jul 13, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from ve...Show more |
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack. |
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability. |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreNov 21, 2024 Jul 3, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions a...Show more |
1Atlassian 2Jira Jira Software Data CenterNov 21, 2024 Jul 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server an...Show more |
1Atlassian 2Jira Data Center Jira ServerNov 21, 2024 Jul 3, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8....Show more |
1Atlassian 2Jira Jira Software Data CenterNov 21, 2024 Jul 3, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affec...Show more |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreNov 21, 2024 Jul 1, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names...Show more |