Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Center MEDIUM 5.3
CVE-2020-36286

The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.…

Fix: 8.5.13 / 8.13.5+
Fix from $1,600 2021-04-01
Data Center HIGH 7.2
CVE-2021-26070

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via…

Fix: 8.13.3 / 8.14.1+
Fix from $1,950 2021-03-22
Data Center MEDIUM 5.3
CVE-2021-26069

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project k…

Fix: 8.5.11 / 8.13.3+
Fix from $1,600 2021-03-22
Crowd MEDIUM 5.3
CVE-2020-36240

The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to …

Fix: 4.0.4 / 4.1.2+
Fix from $1,600 2021-03-01
Jira Server For Slack HIGH 8.8
CVE-2021-26068

An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via …

Fix: 2.0.15+
Fix from $1,950 2021-02-22
Confluence Data Center MEDIUM 5.3
CVE-2020-29448

The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and…

Fix: 6.13.18 / 7.4.6+
Fix from $1,600 2021-02-22
Data Center MEDIUM 5.3
CVE-2020-29453EPSS 23%

The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 bef…

Fix: 8.5.11 / 8.13.3+
Fix from $1,600 2021-02-22
Atlassian Gadgets MEDIUM 5.0
CVE-2020-36232

The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, f…

Fix: 4.2.37 / 4.3.2.4+
Fix from $1,600 2021-02-22
Alfresco Enterprise Content Management HIGH 8.8
CVE-2020-12873

An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a w…

Fix: 6.2.1+
Fix from $1,950 2021-02-19
Bitbucket HIGH 7.8
CVE-2020-36233

The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before…

Fix: 6.10.9 / 7.6.4+
Fix from $1,950 2021-02-18
Jira MEDIUM 6.1
CVE-2020-36236

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (…

Fix: 8.5.11 / 8.13.3+
Fix from $1,600 2021-02-15
Jira MEDIUM 5.3
CVE-2020-36235

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an In…

Fix: 8.13.2 / 8.14.1+
Fix from $1,600 2021-02-15
Data Center MEDIUM 5.3
CVE-2020-36237

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Dis…

Fix: 8.15.0+
Fix from $1,600 2021-02-15
Bamboo MEDIUM 5.3
CVE-2021-26067

Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory …

Fix: 7.2.2+
Fix from $1,600 2021-01-28
Confluence Data Center MEDIUM 6.5
CVE-2020-29450

Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Serv…

Fix: 7.2.0+
Fix from $1,600 2021-01-19
Crucible MEDIUM 5.3
CVE-2020-29446

Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulner…

Fix: 4.8.5+
Fix from $1,600 2021-01-18
Automation For Jira MEDIUM 5.4
CVE-2020-14193

Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF…

Fix: 7.1.15+
Fix from $1,600 2020-11-30
Crucible HIGH 7.5
CVE-2020-14190

Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affec…

Fix: 4.8.4+
Fix from $1,950 2020-11-25
Crucible HIGH 7.5
CVE-2020-14191

Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnera…

Fix: 4.8.4+
Fix from $1,950 2020-11-25
Jira Create CRITICAL 9.8
CVE-2020-14188

The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in th…

Fix: 2.0.1+
Fix from $2,300 2020-11-09
Jira Comment CRITICAL 9.8
CVE-2020-14189

The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the c…

Fix: 2.0.2+
Fix from $2,300 2020-11-09
Jira MEDIUM 5.3
CVE-2020-14185

Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOper…

Fix: 7.13.18 / 8.5.9+
Fix from $1,600 2020-10-15
Jira MEDIUM 5.4
CVE-2020-14184

Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerabili…

Fix: 8.5.9 / 8.12.3+
Fix from $1,600 2020-10-12
Crowd HIGH 7.5
CVE-2019-20902

Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.…

Fix: 3.4.6 / 3.5.1+
Fix from $1,950 2020-10-01
Editor Core MEDIUM 5.4
CVE-2019-20903

The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a C…

Fix: 113.1.5+
Fix from $1,600 2020-10-01
Jira Server MEDIUM 6.5
CVE-2020-14177

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial o…

Fix: 7.13.16 / 8.5.7+
Fix from $1,600 2020-09-21
Jira Data Center MEDIUM 5.3
CVE-2020-14179EPSS 76%

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names vi…

Fix: 8.5.8 / 8.11.1+
Fix from $1,600 2020-09-21
Data Center MEDIUM 5.3
CVE-2020-14181EPSS 100%

Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabili…

Fix: 7.13.6 / 8.5.7+
Fix from $1,600 2020-09-17
Jira HIGH 7.5
CVE-2020-14178

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerabili…

Fix: 7.13.7 / 8.5.8+
Fix from $1,950 2020-09-01
Fisheye MEDIUM 6.5
CVE-2017-18112

Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability i…

Fix: 4.8.3+
Fix from $1,600 2020-08-05