Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Crucible MEDIUM 5.3
CVE-2020-4016

The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote att…

Fix: 4.8.1+
Fix from $1,600 2020-06-01
Crucible MEDIUM 5.3
CVE-2020-4017

The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remo…

Fix: 4.8.1+
Fix from $1,600 2020-06-01
Confluence Server MEDIUM 6.1
CVE-2019-20102

The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 …

Fix: 6.15.5+
Fix from $1,600 2020-04-22
Subversion Application Lifecycle Management MEDIUM 6.1
CVE-2020-9344EPSS 5%

Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.

Fix: 8.8.2+
Fix from $1,600 2020-03-20
Greenhopper MEDIUM 5.4
CVE-2012-1500

Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.

Fix: 5.9.8+
Fix from $1,600 2020-02-13
Jira Server HIGH 7.8
CVE-2019-20400

The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environ…

Fix: 8.5.2 / 8.6.0+
Fix from $1,950 2020-02-06
Confluence HIGH 7.8
CVE-2019-20406

The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows …

Fix: 7.0.5+
Fix from $1,950 2020-02-06
Crowd HIGH 7.5
CVE-2019-20104

The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denia…

Fix: 3.2.11 / 3.3.8+
Fix from $1,950 2020-02-06
Jira Server MEDIUM 6.5
CVE-2019-20401

Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished bei…

Fix: 8.5.2 / 8.6.0+
Fix from $1,600 2020-02-06
Jira Data Center MEDIUM 5.3
CVE-2019-20403

The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an…

Fix: 8.5.5+
Fix from $1,600 2020-02-06
Bitbucket HIGH 8.8
CVE-2019-15010

Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from versio…

Fix: 5.6.11 / 6.0.11+
Fix from $1,950 2020-01-15
Bitbucket HIGH 8.8
CVE-2019-15012

Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from…

Fix: 5.6.11 / 6.0.11+
Fix from $1,950 2020-01-15
Bitbucket HIGH 8.8
CVE-2019-20097

Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6…

Fix: 5.6.11 / 6.0.11+
Fix from $1,950 2020-01-15
Confluence MEDIUM 6.5
CVE-2019-15006

There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This pl…

Fix: 6.13.10 / 6.15.10+
Fix from $1,600 2019-12-19
Crowd MEDIUM 6.5
CVE-2017-18107

Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users…

Fix: 3.1.1+
Fix from $1,600 2019-12-17
Saml Single Sign On HIGH 7.5
CVE-2019-13347

An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Co…

Fix: after 3.2.2
Fix from $1,950 2019-12-13
Crucible MEDIUM 6.1
CVE-2019-15008

The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or…

Fix: 4.7.3+
Fix from $1,600 2019-12-11
Jira Service Desk HIGH 7.5
CVE-2019-15004

The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4…

Fix: 3.9.17 / 3.16.10+
Fix from $1,950 2019-11-07
Jira Service Desk MEDIUM 5.3
CVE-2019-15003

The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4…

Fix: 3.9.17 / 3.16.10+
Fix from $1,600 2019-11-07
Bitbucket CRITICAL 9.8
CVE-2019-15000EPSS 8%

The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed…

Fix: 5.16.10 / 6.0.10+
Fix from $2,300 2019-09-19
Jira Service Desk HIGH 7.5
CVE-2019-14994EPSS 6%

The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before…

Fix: 3.9.16 / 3.16.8+
Fix from $1,950 2019-09-19
Jira Server HIGH 7.2
CVE-2019-15001EPSS 11%

The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before…

Fix: 7.6.16 / 7.13.8+
Fix from $1,950 2019-09-19
Jira Server MEDIUM 6.5
CVE-2019-8451EPSS 94%

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network reso…

Fix: 8.4.0+
Fix from $1,600 2019-09-11
Jira MEDIUM 5.3
CVE-2019-8449EPSS 85%

The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosu…

Fix: 8.4.0+
Fix from $1,600 2019-09-11
Jira Server MEDIUM 6.5
CVE-2019-14998

The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its pro…

Fix: 8.4.0+
Fix from $1,600 2019-09-11
Jira Server MEDIUM 6.1
CVE-2019-14996

The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbi…

Fix: 7.13.7 / 8.3.3+
Fix from $1,600 2019-09-11
Jira Server MEDIUM 5.3
CVE-2019-14995

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name e…

Fix: 8.4.0+
Fix from $1,600 2019-09-11
Confluence HIGH 8.8
CVE-2019-3394EPSS 11%

There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to ed…

Fix: 6.6.16 / 6.13.7+
Fix from $1,950 2019-08-29
Jira MEDIUM 6.5
CVE-2019-11587

Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 bef…

Fix: 7.13.6 / 8.2.3+
Fix from $1,600 2019-08-23
Jira Server MEDIUM 6.1
CVE-2019-11589

The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.…

Fix: 7.13.6 / 8.2.3+
Fix from $1,600 2019-08-23