Skip to main content

Vendor archive

atlassian CVEs

Beta · best-effort

466 CVEs tagged to vendor atlassian47 Critical, 121 High, 294 Medium, 4 Low, 0 Unrated.

CVE-2017-16864

Published Jan 12, 2018

The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16862

Published Jan 12, 2018

The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (C…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14594

Published Jan 12, 2018

The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScri…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14590

Published Dec 13, 2017

Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an ex…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14589

Published Dec 13, 2017

It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who h…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16857

Published Dec 5, 2017

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16856

Published Dec 5, 2017

The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in va…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14591

Published Nov 29, 2017

Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to e…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14586

Published Nov 27, 2017

The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at or above version 4.0 and befo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-9514

Published Oct 12, 2017

Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14588

Published Oct 11, 2017

Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabili…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14587

Published Oct 11, 2017

The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site sc…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6576

Published Oct 3, 2017

Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9512

Published Aug 24, 2017

The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9510

Published Aug 24, 2017

The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnera…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9509

Published Aug 24, 2017

The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerab…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9508

Published Aug 24, 2017

Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabili…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9507

Published Aug 24, 2017

The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripti…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9506

Published Aug 23, 2017

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-9505

Published Jun 15, 2017

Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker wh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8907

Published Jun 14, 2017

Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8080

Published May 5, 2017

Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving image uploads.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8058

Published May 5, 2017

Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 466 CVEsPage 17 of 19