← Back

Atlassian

atlassian

466 CVEs • 59 products

Products (59)

Click to collapse
Toggle
Jira
jira
Jira Server
jira_server
Fisheye
fisheye
Crucible
crucible
Data Center
data_center
Bamboo
bamboo
Crowd
crowd
Bitbucket
bitbucket
Confluence
confluence
Sourcetree
sourcetree
Jira Align
jira_align
Hipchat
hipchat
Floodlight
floodlight
Agiloft
agiloft
Companion
companion
Crowd2
crowd2
Jira Core
jira_core
Oauth
oauth
Http Library
http_library
Cloudtoken
cloudtoken
Greenhopper
greenhopper
Editor Core
editor-core
Jira Create
jira_create
Jira Comment
jira_comment
Atlasboard
atlasboard
Bamboo Server
bamboo_server

CVEs (466)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Aug 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via...Show more
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Aug 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site reque...Show more
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may...Show more
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.Show less
1Atlassian
1Jira
Nov 21, 2024
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.
1Atlassian
1Html Include And Replace Macro
Nov 21, 2024
Aug 14, 2019
N/A· v4
6.8 MEDIUM· v3
6.0 MEDIUM· v2
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
1Atlassian
1Jira Server
Nov 21, 2024
Aug 13, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
1Atlassian
1Jira Server
Oct 24, 2025
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulne...Show more
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.Show less
1Atlassian
1Jira
Nov 21, 2024
Aug 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter.
1Atlassian
1Jira
Nov 21, 2024
Aug 9, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.
5Apache
AtlassianNetapp+2 more
31Active Iq Unified Manager
Apache Batik MapviewerBanking Enterprise Originations+28 more
Nov 21, 2024
Jul 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
1Atlassian
1Jira
Nov 21, 2024
Jun 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
1Atlassian
1Sourcetree
Nov 21, 2024
Jun 14, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI.
1Atlassian
1Bitbucket
Nov 21, 2024
Jun 3, 2019
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version...Show more
Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.Show less
1Atlassian
1Crowd
Oct 24, 2025
Jun 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance...Show more
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
May 22, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to...Show more
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
May 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira web...Show more
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
May 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrec...Show more
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
May 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabili...Show more
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
May 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
1Atlassian
1Jira Server
Nov 21, 2024
May 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parame...Show more
The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter.Show less