Skip to main content

Vendor archive

atlassian CVEs

Beta · best-effort

471 CVEs tagged to vendor atlassian48 Critical, 125 High, 294 Medium, 4 Low, 0 Unrated.

CVE-2021-39117

Published Aug 30, 2021

The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scr…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26086

Published Aug 16, 2021

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-37843

Published Aug 2, 2021

The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided).…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18113

Published Aug 2, 2021

The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their mali…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26077

Published May 10, 2021

Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Spring Boot is a Java Spring Boo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29445

Published May 7, 2021

Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request for…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26074

Published Apr 16, 2021

Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atl…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26073

Published Apr 16, 2021

Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect app…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 471 CVEsPage 6 of 19