← Back

Atlassian

atlassian

466 CVEs • 59 products

Products (59)

Click to collapse
Toggle
Jira
jira
Jira Server
jira_server
Fisheye
fisheye
Crucible
crucible
Data Center
data_center
Bamboo
bamboo
Crowd
crowd
Bitbucket
bitbucket
Confluence
confluence
Sourcetree
sourcetree
Jira Align
jira_align
Hipchat
hipchat
Floodlight
floodlight
Agiloft
agiloft
Companion
companion
Crowd2
crowd2
Jira Core
jira_core
Oauth
oauth
Http Library
http_library
Cloudtoken
cloudtoken
Greenhopper
greenhopper
Editor Core
editor-core
Jira Create
jira_create
Jira Comment
jira_comment
Atlasboard
atlasboard
Bamboo Server
bamboo_server

CVEs (466)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Navigator Links
Nov 21, 2024
Jun 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote att...Show more
The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including those that are restricted or otherwise hidden, through an incorrect authorization check.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilte...Show more
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.Show less
1Atlassian
4Jira
Jira Data CenterJira Server+1 more
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in th...Show more
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.Show less
1Atlassian
1Companion
Nov 21, 2024
Jun 1, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe file...Show more
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.Show less
1Atlassian
1Companion
Nov 21, 2024
Jun 1, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability...Show more
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Jun 1, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application l...Show more
The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application links via an information disclosure vulnerability.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an inform...Show more
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Jun 1, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Jun 1, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.
1Atlassian
1Confluence Server
Nov 21, 2024
Apr 22, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS)...Show more
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.Show less
1Atlassian
1Subversion Application Lifecycle Management
Nov 21, 2024
Mar 20, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.
1Atlassian
2Jira Data Center
Jira Server
Nov 21, 2024
Mar 17, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access t...Show more
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.Show less
1Atlassian
1Application Links
Nov 21, 2024
Mar 17, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1,...Show more
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.Show less
1Atlassian
2Greenhopper
Jira
Nov 21, 2024
Feb 13, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.
1Atlassian
3Jira
Jira Data CenterJira Server
Nov 21, 2024
Feb 12, 2020
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 b...Show more
The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.2, and from version 7.1.0 before version 7.1.3. The vulnerable plugin is used by Atlassian Jira Server and Data Center before version 8.7.0. An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.Show less
1Atlassian
2Jira Data Center
Jira Server
Nov 21, 2024
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrat...Show more
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.Show less
1Atlassian
2Jira Data Center
Jira Server
Nov 21, 2024
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administra...Show more
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.Show less
1Atlassian
2Confluence
Confluence Server
Nov 21, 2024
Feb 6, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a dir...Show more
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.Show less