Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Crucible HIGH 7.5
CVE-2017-9512

The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive in…

Fix: after 4.4.0
Fix from $1,950 2017-08-24
Crucible MEDIUM 5.4
CVE-2017-9507

The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaS…

Fix: after 4.4.0
Fix from $1,600 2017-08-24
Crucible MEDIUM 5.4
CVE-2017-9508

Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross si…

Mitigation only
Fix from $1,600 2017-08-24
Crucible MEDIUM 5.4
CVE-2017-9509

The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross…

Fix: after 4.4.0
Fix from $1,600 2017-08-24
Fisheye MEDIUM 5.4
CVE-2017-9510

The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cros…

Fix: after 4.4.0
Fix from $1,600 2017-08-24
Oauth MEDIUM 6.1
CVE-2017-9506EPSS 72%

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote a…

No fix yet
Fix from $1,600 2017-08-23
Bamboo HIGH 8.8
CVE-2017-8907

Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and t…

Mitigation only
Fix from $1,950 2017-06-14
Hipchat Server HIGH 8.8
CVE-2017-8080

Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving im…

Fix: after 2.2.3
Fix from $1,950 2017-05-05
Hipchat MEDIUM 5.9
CVE-2017-8058

Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate …

Fix: after 3.16.1
Fix from $1,600 2017-05-05
Sourcetree CRITICAL 9.8
CVE-2017-8768EPSS 8%

Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS co…

Fix: after 2.5c
Fix from $2,300 2017-05-04
Confluence Server HIGH 7.5
CVE-2017-7415

Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.

No fix yet
Fix from $1,950 2017-04-27
Hipchat Server CRITICAL 9.1
CVE-2017-7357

Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a fil…

Fix: after 2.2.2
Fix from $2,300 2017-04-14
Jira CRITICAL 9.8
CVE-2017-5983EPSS 16%

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers…

Mitigation only
Fix from $2,300 2017-04-10
Jira HIGH 8.8
CVE-2016-4319

Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

Fix: after 7.1.8
Fix from $1,950 2017-04-10
Confluence MEDIUM 5.4
CVE-2016-4317

Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.

Fix: after 5.9.10
Fix from $1,600 2017-04-10
Jira MEDIUM 6.1
CVE-2016-6285

Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inj…

Fix: after 7.2.1
Fix from $1,600 2017-01-31
Confluence Server HIGH 7.5
CVE-2016-6668

The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat …

No fix yet
Fix from $1,950 2017-01-23
Confluence MEDIUM 6.1
CVE-2016-6283

Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the…

Fix: after 5.10.5
Fix from $1,600 2017-01-18
Crowd CRITICAL 9.8
CVE-2016-6496

The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP att…

Fix: after 2.8.4
Fix from $2,300 2016-12-09
Bamboo CRITICAL 9.8
CVE-2016-5229EPSS 7%

Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers …

Fix: after 5.11.3
Fix from $2,300 2016-08-02
Confluence MEDIUM 6.1
CVE-2015-8398

Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the…

Fix: after 5.8.16
Fix from $1,600 2016-04-11
Bamboo CRITICAL 9.1
CVE-2015-8361

Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers …

Patch available
Fix from $2,300 2016-02-08
Bamboo CRITICAL 9.8
CVE-2015-8360

An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serializ…

Patch available
Fix from $2,300 2016-02-08
Bamboo CRITICAL 9.8
CVE-2014-9757

The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execu…

Patch available
Fix from $2,300 2016-02-08
Hipchat MEDIUM 6.5
CVE-2015-5603EPSS 59%

The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors…

Fix: after 6.29.2
Fix from $1,600 2015-09-21
Confluence Server MEDIUM 6.8
CVE-2012-6342

Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication o…

No fix yet
Fix from $1,600 2014-05-13
Crowd HIGH 7.5
CVE-2013-3926

Atlassian Crowd 2.6.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to a "symmetric backdoor." NOTE: as of 2…

No fix yet
Fix from $1,950 2013-07-01
Crowd MEDIUM 5.8
CVE-2013-3925

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to in…

No fix yet
Fix from $1,600 2013-07-01
Bamboo CRITICAL 9.1
CVE-2012-2926EPSS 67%

Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, …

Fix: 2.0.9 / 2.1.2+
Fix from $2,300 2012-05-22
Jira MEDIUM 6.4
CVE-2012-2928

The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-part…

Fix: after 5.0.0
Fix from $1,600 2012-05-22