Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Confluence MEDIUM 5.4
CVE-2017-18083

The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cros…

Fix: 6.4.0+
Fix from $1,600 2018-02-02
Bamboo HIGH 8.8
CVE-2017-18042

The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via …

Fix: 6.3.1+
Fix from $1,950 2018-02-02
Bitbucket MEDIUM 6.5
CVE-2017-18037

The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0…

Fix: 4.14.11 / 5.0.9+
Fix from $1,600 2018-02-02
Jira MEDIUM 6.1
CVE-2017-18039

The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaSc…

Fix: 7.4.4+
Fix from $1,600 2018-02-02
Crucible MEDIUM 5.4
CVE-2017-18034

The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to …

Fix: 4.5.1+
Fix from $1,600 2018-02-02
Bamboo MEDIUM 5.4
CVE-2017-18040

The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via…

Fix: 6.2+
Fix from $1,600 2018-02-02
Bamboo MEDIUM 5.4
CVE-2017-18041

The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaS…

Fix: 6.2.0+
Fix from $1,600 2018-02-02
Bitbucket MEDIUM 5.3
CVE-2017-18038

The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files…

Fix: 5.6.0+
Fix from $1,600 2018-02-02
Fisheye CRITICAL 9.8
CVE-2017-16861

It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. An attacker who can a…

Fix: 4.4.5 / 4.5.2+
Fix from $2,300 2018-02-01
Crowd MEDIUM 6.8
CVE-2017-16858

The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an …

Fix: 3.1.2+
Fix from $1,600 2018-01-31
Activity Streams MEDIUM 5.4
CVE-2017-9513

Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence…

Fix: 6.3.0+
Fix from $1,600 2018-01-29
Sourcetree HIGH 8.8
CVE-2017-14592EPSS 6%

Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit …

Fix: 2.7+
Fix from $1,950 2018-01-26
Sourcetree HIGH 8.8
CVE-2017-14593EPSS 6%

Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commi…

Fix: 2.4.7.0+
Fix from $1,950 2018-01-26
Jira MEDIUM 6.1
CVE-2017-16863

The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting …

Fix: 7.5.3+
Fix from $1,600 2018-01-18
Jira MEDIUM 6.5
CVE-2017-18033

The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external syste…

Fix: 7.6.1+
Fix from $1,600 2018-01-18
Jira MEDIUM 5.3
CVE-2017-16865

The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server S…

Fix: 7.6.1+
Fix from $1,600 2018-01-17
Jira MEDIUM 6.1
CVE-2017-14594

The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inj…

Fix: 7.2.12 / 7.6.1+
Fix from $1,600 2018-01-12
Jira MEDIUM 6.1
CVE-2017-16864

The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scri…

Fix: 7.4.2+
Fix from $1,600 2018-01-12
Bamboo CRITICAL 9.6
CVE-2017-14589

It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administra…

Fix: 6.1.6 / 6.2.5+
Fix from $2,300 2017-12-13
Bamboo CRITICAL 9.1
CVE-2017-14590

Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a re…

Fix: 6.1.6 / 6.2.5+
Fix from $2,300 2017-12-13
Bitbucket Auto Unapprove Plugin HIGH 8.5
CVE-2017-16857

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. Th…

Mitigation only
Fix from $1,950 2017-12-05
Confluence MEDIUM 6.1
CVE-2017-16856

The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripti…

Fix: 6.5.2+
Fix from $1,600 2017-12-05
Crucible CRITICAL 9.0
CVE-2017-14591

Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial reposit…

Fix: 4.4.3+
Fix from $2,300 2017-11-29
Hipchat CRITICAL 9.8
CVE-2017-14586

The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at…

Fix: 4.30+
Fix from $2,300 2017-11-27
Hipchat Data Center HIGH 7.2
CVE-2017-14585

A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in…

Fix: 2.2.6 / 3.1.0+
Fix from $1,950 2017-11-27
Bamboo HIGH 8.8
CVE-2017-9514

Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which c…

Mitigation only
Fix from $1,950 2017-10-12
Crucible MEDIUM 6.1
CVE-2017-14588

Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross si…

Fix: after 4.4.1
Fix from $1,600 2017-10-11
Crucible MEDIUM 5.4
CVE-2017-14587

The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or …

Fix: after 4.4.1
Fix from $1,600 2017-10-11
Bamboo HIGH 8.8
CVE-2015-6576

Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an …

Fix: 5.8.5 / 5.9.7+
Fix from $1,950 2017-10-03
Crucible HIGH 7.5
CVE-2017-9511

The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a p…

Fix: after 4.4.0
Fix from $1,950 2017-08-24