Skip to main content

Vendor archive

atlassian CVEs

Beta · best-effort

471 CVEs tagged to vendor atlassian48 Critical, 125 High, 294 Medium, 4 Low, 0 Unrated.

CVE-2018-5229

Published Jul 16, 2018

The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13387

Published Jul 16, 2018

The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13389

Published Jul 10, 2018

The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a co…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13388

Published Jul 10, 2018

The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XS…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000617

Published Jul 9, 2018

Atlassian Floodlight Atlassian Floodlight Controller version 1.2 and earlier versions contains a Denial of Service vulnerability in Forwarding module that can result in Improper t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16859

Published Jun 28, 2018

The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read fil…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5231

Published May 16, 2018

The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 bef…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5230

Published May 14, 2018

The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16860

Published May 14, 2018

The invalidRedirectUrl template in Atlassian Application Links before version 5.2.7, from version 5.3.0 before version 5.3.4 and from version 5.4.0 before version 5.4.3 allows rem…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5226

Published Apr 25, 2018

There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5228

Published Apr 24, 2018

The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vu…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18102

Published Apr 17, 2018

The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5227

Published Apr 10, 2018

Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18100

Published Apr 10, 2018

The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18098

Published Apr 6, 2018

The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18097

Published Apr 6, 2018

The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18096

Published Apr 4, 2018

The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5224

Published Mar 29, 2018

Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has pe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5223

Published Mar 29, 2018

Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attac…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5225

Published Mar 22, 2018

In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18094

Published Mar 22, 2018

Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject ar…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6569

Published Feb 21, 2018

Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thre…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18095

Published Feb 19, 2018

The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not ha…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18093

Published Feb 19, 2018

Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-375 of 471 CVEsPage 15 of 19