← Back

Atlassian

atlassian

466 CVEs • 59 products

Products (59)

Click to collapse
Toggle
Jira
jira
Jira Server
jira_server
Fisheye
fisheye
Crucible
crucible
Data Center
data_center
Bamboo
bamboo
Crowd
crowd
Bitbucket
bitbucket
Confluence
confluence
Sourcetree
sourcetree
Jira Align
jira_align
Hipchat
hipchat
Floodlight
floodlight
Agiloft
agiloft
Companion
companion
Crowd2
crowd2
Jira Core
jira_core
Oauth
oauth
Http Library
http_library
Cloudtoken
cloudtoken
Greenhopper
greenhopper
Editor Core
editor-core
Jira Create
jira_create
Jira Comment
jira_comment
Atlasboard
atlasboard
Bamboo Server
bamboo_server

CVEs (466)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Feb 13, 2019
N/A· v4
4.1 MEDIUM· v3
4.0 MEDIUM· v2
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10...Show more
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in some cases obtain service information from internal network resources via a Server Side Request Forgery (SSRF) vulnerability.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Feb 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HT...Show more
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.Show less
1Atlassian
1Crowd
Nov 21, 2024
Jan 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resource...Show more
Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources.Show less
1Atlassian
1Universal Plugin Manager
Nov 21, 2024
Jan 18, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of servic...Show more
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR.Show less
1Atlassian
1Crowd2
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system...Show more
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.Show less
1Atlassian
1Crowd2
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker...Show more
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings.Show less
1Atlassian
1Hipchat
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkin...Show more
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.Show less
1Atlassian
1Hipchat
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipCha...Show more
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Atlassian
1Sourcetree
Nov 21, 2024
Nov 5, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial re...Show more
There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.Show less
1Atlassian
1Sourcetree
Nov 21, 2024
Nov 5, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial reposi...Show more
There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3,...Show more
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allow remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Oct 23, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before v...Show more
The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allows remote attackers to obtain a user's Cross-site request forgery (CSRF) token through an open redirect vulnerability.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Oct 23, 2018
N/A· v4
4.7 MEDIUM· v3
6.5 MEDIUM· v2
Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 befo...Show more
Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allow remote attackers who have obtained access to administrator's session to access certain administrative resources without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Oct 16, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Sep 18, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Aug 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10...Show more
Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the epic colour field of an issue while an issue is being moved.Show less
1Atlassian
2Jira
Jira Server
Nov 21, 2024
Aug 28, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 befo...Show more
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain the email address of the reporter and assignee user of an issue despite the configured email visibility setting being set to hidden.Show less
1Atlassian
1Questions For Confluence
Nov 21, 2024
Aug 15, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify...Show more
The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.Show less
1Atlassian
1Questions For Confluence
Nov 21, 2024
Aug 15, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers...Show more
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Aug 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.