Atlassian
atlassian
466 CVEs • 59 products
Products (59)
Click to collapseToggle
Products (59)
Click to collapse
CVEs (466)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote att...Show more |
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilte...Show more |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreNov 21, 2024 Jun 1, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in th...Show more |
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe file...Show more |
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability...Show more |
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability. |
The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application l...Show more |
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an inform...Show more |
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability. |
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability. |
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives. |
1Atlassian 1Confluence Server Nov 21, 2024 Apr 22, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS)...Show more |
1Atlassian 1Subversion Application Lifecycle Management Nov 21, 2024 Mar 20, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations. |
1Atlassian 2Jira Data Center Jira ServerNov 21, 2024 Mar 17, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access t...Show more |
1Atlassian 1Application Links Nov 21, 2024 Mar 17, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1,...Show more |
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code. |
1Atlassian 3Jira Jira Data CenterJira ServerNov 21, 2024 Feb 12, 2020 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 b...Show more |
1Atlassian 2Jira Data Center Jira ServerNov 21, 2024 Feb 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrat...Show more |
1Atlassian 2Jira Data Center Jira ServerNov 21, 2024 Feb 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administra...Show more |
1Atlassian 2Confluence Confluence ServerNov 21, 2024 Feb 6, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a dir...Show more |