Filtered by vendor Atlassian
Subscribe
Total
433 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-18100 | 1 Atlassian | 1 Jira | 2018-05-14 | 4.3 MEDIUM | 6.1 MEDIUM |
The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters. | |||||
CVE-2017-18096 | 1 Atlassian | 1 Application Links | 2018-05-10 | 4.0 MEDIUM | 7.2 HIGH |
The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative rights to access the content of internal network resources via a Server Side Request Forgery (SSRF) by creating an OAuth application link to a location they control and then redirecting access from the linked location's OAuth status rest resource to an internal location. When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information. | |||||
CVE-2017-18098 | 1 Atlassian | 1 Jira | 2018-05-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields. | |||||
CVE-2017-18097 | 1 Atlassian | 1 Jira | 2018-05-09 | 3.5 LOW | 5.4 MEDIUM |
The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card. | |||||
CVE-2018-5224 | 2 Atlassian, Microsoft | 2 Bamboo, Windows | 2018-04-24 | 9.0 HIGH | 8.8 HIGH |
Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that has a non-linked Mercurial repository, or create a plan in Bamboo either globally or in a project using Bamboo Specs can can execute code of their choice on systems that run a vulnerable version of Bamboo on the Windows operating system. All versions of Bamboo starting with 2.7.0 before 6.3.3 (the fixed version for 6.3.x) and from version 6.4.0 before 6.4.1 (the fixed version for 6.4.x) running on the Windows operating system are affected by this vulnerability. | |||||
CVE-2018-5223 | 1 Atlassian | 2 Crucible, Fisheye | 2018-04-24 | 6.5 MEDIUM | 7.2 HIGH |
Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repository in Fisheye or Crucible can execute code of their choice on systems that run a vulnerable version of Fisheye or Crucible on the Windows operating system. All versions of Fisheye and Crucible before 4.4.6 (the fixed version for 4.4.x) and from 4.5.0 before 4.5.3 (the fixed version for 4.5.x) are affected by this vulnerability. | |||||
CVE-2018-5225 | 1 Atlassian | 1 Bitbucket | 2018-04-20 | 6.5 MEDIUM | 9.9 CRITICAL |
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository. | |||||
CVE-2017-18094 | 1 Atlassian | 2 Crucible, Fisheye | 2018-04-18 | 3.5 LOW | 4.8 MEDIUM |
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the base path setting of a configured file system repository. | |||||
CVE-2015-6569 | 1 Atlassian | 1 Floodlight | 2018-03-19 | 4.3 MEDIUM | 5.9 MEDIUM |
Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a state manipulation attack. | |||||
CVE-2017-18088 | 1 Atlassian | 1 Bitbucket | 2018-03-15 | 4.3 MEDIUM | 4.3 MEDIUM |
Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.6 (the fixed version for 5.5.x), from version 5.6.0 before 5.6.3 (the fixed version for 5.6.x), from version 5.7.0 before 5.7.1 (the fixed version for 5.7.x) and before 5.8.0 allow remote attackers to conduct clickjacking attacks via framing various resources that lacked clickjacking protection. | |||||
CVE-2017-18093 | 1 Atlassian | 2 Crucible, Fisheye | 2018-03-12 | 3.5 LOW | 4.8 MEDIUM |
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the location setting of a configured repository. | |||||
CVE-2017-18092 | 1 Atlassian | 1 Crucible | 2018-03-12 | 3.5 LOW | 5.4 MEDIUM |
The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of a comment on the snippet. | |||||
CVE-2017-18091 | 1 Atlassian | 2 Crucible, Fisheye | 2018-03-06 | 3.5 LOW | 4.8 MEDIUM |
The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the filename of a backup. | |||||
CVE-2017-18090 | 1 Atlassian | 1 Fisheye | 2018-03-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author. | |||||
CVE-2017-18089 | 1 Atlassian | 1 Crucible | 2018-03-06 | 3.5 LOW | 5.4 MEDIUM |
The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review. | |||||
CVE-2017-18037 | 1 Atlassian | 1 Bitbucket | 2018-02-24 | 4.0 MEDIUM | 6.5 MEDIUM |
The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), from version 5.1.0 before 5.1.8 (the fixed version for 5.1.x), from version 5.2.0 before 5.2.6 (the fixed version for 5.2.x), from version 5.3.0 before 5.3.4 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.2 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.1 (the fixed version for 5.5.x) and before 5.6.0 allows remote attackers to read arbitrary files via a path traversal vulnerability through the name of a git tag. | |||||
CVE-2016-4319 | 1 Atlassian | 1 Jira | 2018-02-16 | 6.8 MEDIUM | 8.8 HIGH |
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings. | |||||
CVE-2016-4318 | 1 Atlassian | 1 Jira | 2018-02-16 | 3.5 LOW | 4.8 MEDIUM |
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name. | |||||
CVE-2016-4317 | 1 Atlassian | 1 Confluence | 2018-02-16 | 3.5 LOW | 5.4 MEDIUM |
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. | |||||
CVE-2017-18083 | 1 Atlassian | 1 Confluence | 2018-02-15 | 3.5 LOW | 5.4 MEDIUM |
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file. |