Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Confluence Data Center MEDIUM 5.4
CVE-2020-14175

Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scrip…

Fix: 7.4.2 / 7.5.2+
Fix from $1,600 2020-07-24
Jira MEDIUM 6.1
CVE-2019-20901

The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a diffe…

Fix: 8.5.2+
Fix from $1,600 2020-07-13
Jira HIGH 7.5
CVE-2019-20898

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the …

Fix: 8.8.0+
Fix from $1,950 2020-07-13
Jira MEDIUM 5.3
CVE-2019-20899

The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests …

Fix: 8.5.4 / 8.6.1+
Fix from $1,600 2020-07-13
Jira MEDIUM 6.5
CVE-2019-20897

The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a cr…

Fix: 8.5.4 / 8.6.2+
Fix from $1,600 2020-07-13
Bitbucket MEDIUM 6.5
CVE-2020-14171

Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a …

Fix: 7.2.4+
Fix from $1,600 2020-07-09
Jira CRITICAL 9.8
CVE-2020-14172

This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. Th…

Fix: 7.13.0 / 8.5.0+
Fix from $2,300 2020-07-03
Jira Data Center HIGH 7.8
CVE-2019-20419

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomc…

Fix: 8.5.5 / 8.7.2+
Fix from $1,950 2020-07-03
Jira MEDIUM 5.4
CVE-2020-14173

The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript …

Fix: 8.5.4 / 8.6.2+
Fix from $1,600 2020-07-03
Jira MEDIUM 6.5
CVE-2019-20418

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Den…

Fix: 8.8.0+
Fix from $1,600 2020-07-03
Jira MEDIUM 6.1
CVE-2020-14169

The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a…

Fix: 8.9.1+
Fix from $1,600 2020-07-01
Jira MEDIUM 6.1
CVE-2020-4022

The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allo…

Fix: 8.5.5 / 8.8.2+
Fix from $1,600 2020-07-01
Jira MEDIUM 5.4
CVE-2020-4024

The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allo…

Fix: 8.5.5 / 8.8.2+
Fix from $1,600 2020-07-01
Jira HIGH 7.5
CVE-2020-14167

The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8…

Fix: 7.13.14 / 8.5.5+
Fix from $1,950 2020-07-01
Jira MEDIUM 6.1
CVE-2020-14164

The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names …

Fix: 8.8.2+
Fix from $1,600 2020-07-01
Jira MEDIUM 5.9
CVE-2020-14168

The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1…

Fix: 7.13.14 / 8.5.5+
Fix from $1,600 2020-07-01
Jira MEDIUM 5.3
CVE-2019-20408

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network reso…

Fix: 8.7.0+
Fix from $1,600 2020-07-01
Jira MEDIUM 5.3
CVE-2020-14165

The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information abo…

Fix: 8.9.0+
Fix from $1,600 2020-07-01
Jira MEDIUM 5.4
CVE-2019-20414

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (…

Fix: 7.13.9 / 8.4.2+
Fix from $1,600 2020-06-29
Jira HIGH 7.5
CVE-2019-20413

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (D…

Fix: 7.13.9 / 8.4.2+
Fix from $1,950 2020-06-29
Jira MEDIUM 6.5
CVE-2019-20410

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnera…

Fix: 7.6.17 / 7.13.9+
Fix from $1,600 2020-06-29
Jira MEDIUM 5.3
CVE-2019-20412

The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following in…

Fix: 7.13.9 / 8.4.2+
Fix from $1,600 2020-06-29
Jira MEDIUM 5.3
CVE-2020-4028

Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situati…

Fix: 8.9.1+
Fix from $1,600 2020-06-23
Jira CRITICAL 9.8
CVE-2019-20409

The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote…

Fix: 8.8.0+
Fix from $2,300 2020-06-23
Companion HIGH 7.8
CVE-2020-4019

The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable …

Fix: 1.0.0+
Fix from $1,950 2020-06-01
Companion HIGH 7.2
CVE-2020-4020

The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server insta…

Fix: 1.0.0+
Fix from $1,950 2020-06-01
Jira MEDIUM 5.4
CVE-2020-4021

Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary …

Fix: 7.13.16 / 8.5.5+
Fix from $1,600 2020-06-01
Crucible MEDIUM 5.4
CVE-2020-4023

The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript vi…

Fix: 4.8.2+
Fix from $1,600 2020-06-01
Crucible HIGH 8.8
CVE-2020-4018

The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site req…

Fix: 4.8.1+
Fix from $1,950 2020-06-01
Crucible MEDIUM 5.4
CVE-2020-4013

The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross…

Fix: 4.8.1+
Fix from $1,600 2020-06-01