Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jira MEDIUM 6.1
CVE-2018-13387

The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before ve…

Fix: 7.6.7 / 7.7.5+
Fix from $1,600 2018-07-16
Universal Plugin Manager MEDIUM 5.4
CVE-2018-5229

The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitra…

Fix: 2.22.9+
Fix from $1,600 2018-07-16
Crucible MEDIUM 5.4
CVE-2018-13388

The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript …

Fix: 4.5.3+
Fix from $1,600 2018-07-10
Floodlight Controller HIGH 7.5
CVE-2018-1000617

Atlassian Floodlight Atlassian Floodlight Controller version 1.2 and earlier versions contains a Denial of Service vulnerability in Forwarding module…

Fix: after 1.2
Fix from $1,950 2018-07-09
Crucible MEDIUM 6.5
CVE-2017-16859

The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allow…

Fix: 4.3.2 / 4.4.3+
Fix from $1,600 2018-06-28
Jira HIGH 7.5
CVE-2018-5231

The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.…

Fix: 7.6.6 / 7.7.4+
Fix from $1,950 2018-05-16
Jira MEDIUM 6.1
CVE-2018-5230EPSS 38%

The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from…

Fix: 7.6.6 / 7.7.4+
Fix from $1,600 2018-05-14
Application Links MEDIUM 6.1
CVE-2017-16860

The invalidRedirectUrl template in Atlassian Application Links before version 5.2.7, from version 5.3.0 before version 5.3.4 and from version 5.4.0 b…

Fix: 5.2.7 / 5.3.4+
Fix from $1,600 2018-05-14
Sourcetree HIGH 8.8
CVE-2018-5226

There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker wi…

Fix: 2.5.5.0+
Fix from $1,950 2018-04-25
Fisheye MEDIUM 6.1
CVE-2018-5228

The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a…

Fix: 4.5.3+
Fix from $1,600 2018-04-24
Jira Server MEDIUM 5.4
CVE-2017-18102

The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScri…

Fix: 7.6.8 / 7.7.1+
Fix from $1,600 2018-04-17
Jira MEDIUM 6.5
CVE-2017-18101

Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 befor…

Fix: 7.6.5 / 7.7.3+
Fix from $1,600 2018-04-10
Jira MEDIUM 6.1
CVE-2017-18100

The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scr…

Fix: 7.8.1+
Fix from $1,600 2018-04-10
Jira MEDIUM 6.1
CVE-2017-18098

The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site…

Fix: 7.6.1+
Fix from $1,600 2018-04-06
Jira MEDIUM 5.4
CVE-2017-18097

The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import the…

Fix: 7.6.1+
Fix from $1,600 2018-04-06
Application Links HIGH 7.2
CVE-2017-18096

The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote…

Fix: 5.2.7 / 5.3.4+
Fix from $1,950 2018-04-04
Bamboo HIGH 8.8
CVE-2018-5224

Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument para…

Fix: 6.3.3 / 6.4.1+
Fix from $1,950 2018-03-29
Fisheye HIGH 7.2
CVE-2018-5223

Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider…

Fix: 4.4.6 / 4.5.3+
Fix from $1,950 2018-03-29
Bitbucket CRITICAL 9.9
CVE-2018-5225

In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (t…

Fix: 5.4.8 / 5.5.8+
Fix from $2,300 2018-03-22
Floodlight MEDIUM 5.9
CVE-2015-6569

Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NUL…

Fix: 1.2+
Fix from $1,600 2018-02-21
Crucible MEDIUM 5.4
CVE-2017-18092

The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to injec…

Fix: 4.4.3+
Fix from $1,600 2018-02-19
Crucible MEDIUM 5.3
CVE-2017-18095

The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comm…

Fix: 4.5.1+
Fix from $1,600 2018-02-19
Fisheye MEDIUM 6.1
CVE-2017-18090

Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject a…

Mitigation only
Fix from $1,600 2018-02-16
Crucible MEDIUM 5.4
CVE-2017-18089

The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject…

Fix: 4.4.3+
Fix from $1,600 2018-02-16
Bitbucket HIGH 7.5
CVE-2017-18087

The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from ver…

Fix: 5.1.7 / 5.2.5+
Fix from $1,950 2018-02-15
Bamboo HIGH 8.8
CVE-2017-18080

The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site requ…

Fix: 6.3.1+
Fix from $1,950 2018-02-02
Bamboo MEDIUM 6.1
CVE-2017-18081

The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scri…

Fix: 6.3.1+
Fix from $1,600 2018-02-02
Confluence MEDIUM 6.1
CVE-2017-18085

The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript …

Fix: 6.6.1+
Fix from $1,600 2018-02-02
Confluence MEDIUM 6.1
CVE-2017-18086

Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site …

Fix: 6.4.2+
Fix from $1,600 2018-02-02
Bamboo MEDIUM 5.4
CVE-2017-18082

The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cr…

Fix: 6.2.3+
Fix from $1,600 2018-02-02