← Back

Atlassian

atlassian

472 CVEs • 59 products

Products (59)

Click to collapse
Toggle
Jira
jira
Jira Server
jira_server
Fisheye
fisheye
Crucible
crucible
Data Center
data_center
Bamboo
bamboo
Crowd
crowd
Bitbucket
bitbucket
Confluence
confluence
Sourcetree
sourcetree
Jira Align
jira_align
Hipchat
hipchat
Floodlight
floodlight
Agiloft
agiloft
Companion
companion
Crowd2
crowd2
Jira Core
jira_core
Oauth
oauth
Http Library
http_library
Cloudtoken
cloudtoken
Greenhopper
greenhopper
Editor Core
editor-core
Jira Create
jira_create
Jira Comment
jira_comment
Atlasboard
atlasboard
Bamboo Server
bamboo_server

CVEs (472)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Bamboo
May 13, 2026
Oct 3, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
1Atlassian
2Crucible
Fisheye
May 13, 2026
Aug 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the...Show more
The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system.Show less
1Atlassian
2Crucible
Fisheye
May 13, 2026
Aug 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked perm...Show more
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.Show less
1Atlassian
1Fisheye
May 13, 2026
Aug 24, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end dat...Show more
The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.Show less
1Atlassian
2Crucible
Fisheye
May 13, 2026
Aug 24, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously...Show more
The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.Show less
1Atlassian
2Crucible
Fisheye
May 13, 2026
Aug 24, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or re...Show more
Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.Show less
1Atlassian
2Crucible
Fisheye
May 13, 2026
Aug 24, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filt...Show more
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.Show less
1Atlassian
1Oauth
May 13, 2026
Aug 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or per...Show more
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).Show less
1Atlassian
1Confluence
May 13, 2026
Jun 15, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive w...Show more
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.Show less
1Atlassian
1Bamboo
May 13, 2026
Jun 14, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a...Show more
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a green build, to create a deployment project and execute arbitrary code on an available Bamboo Agent. By default a local agent is enabled; this means that code execution can occur on the system hosting Bamboo as the user running Bamboo.Show less
1Atlassian
1Hipchat Server
May 13, 2026
May 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving image uploads.
1Atlassian
1Hipchat
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API ca...Show more
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.Show less
1Atlassian
1Sourcetree
May 13, 2026
May 4, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS command execution with a URL substring of sourcetree://cloneRepo/ext:: or...Show more
Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS command execution with a URL substring of sourcetree://cloneRepo/ext:: or sourcetree://checkoutRef/ext:: followed by the command. The Atlassian ID number is SRCTREE-4632.Show less
1Atlassian
1Confluence Server
May 13, 2026
Apr 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.
1Atlassian
1Hipchat Server
May 13, 2026
Apr 14, 2017
N/A· v4
9.1 CRITICAL· v3
6.5 MEDIUM· v2
Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file.
1Atlassian
1Jira
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of...Show more
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.Show less
1Atlassian
1Bitbucket
May 13, 2026
Apr 10, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.
1Atlassian
1Jira
May 13, 2026
Apr 10, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
1Atlassian
1Jira
May 13, 2026
Apr 10, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
1Atlassian
1Confluence
May 13, 2026
Apr 10, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.