Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jira Server MEDIUM 5.4
CVE-2019-8444

The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTM…

Fix: 7.13.6 / 8.3.2+
Fix from $1,600 2019-08-23
Jira Server MEDIUM 5.3
CVE-2019-8445

Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time…

Fix: 7.13.7 / 8.3.2+
Fix from $1,600 2019-08-23
Jira Server MEDIUM 5.3
CVE-2019-8446EPSS 18%

The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation c…

Fix: 8.3.2+
Fix from $1,600 2019-08-23
Jira MEDIUM 6.1
CVE-2019-11584

The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scrip…

Fix: 8.3.2+
Fix from $1,600 2019-08-23
Jira MEDIUM 6.1
CVE-2019-11585

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows r…

Fix: 7.13.6 / 8.2.3+
Fix from $1,600 2019-08-23
Html Include And Replace Macro MEDIUM 6.8
CVE-2019-15053

The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism v…

Fix: after 1.4.2
Fix from $1,600 2019-08-14
Jira Server MEDIUM 5.3
CVE-2019-8448

The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via …

Fix: 7.13.4 / 8.2.2+
Fix from $1,600 2019-08-13
Jira Server CRITICAL 9.8
CVE-2019-11581 KEVEPSS 85%

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. A…

Fix: 7.6.14 / 7.13.5+
Fix from $2,300 2019-08-09
Jira MEDIUM 5.4
CVE-2018-20827

The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (X…

Fix: 7.13.1+
Fix from $1,600 2019-08-09
Jira MEDIUM 6.5
CVE-2019-11583

The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability…

Fix: 8.1.0+
Fix from $1,600 2019-06-26
Sourcetree HIGH 8.8
CVE-2019-11582

An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to ga…

Fix: 3.1.3+
Fix from $1,950 2019-06-14
Crowd CRITICAL 9.8
CVE-2019-11580 KEVEPSS 95%

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthentic…

Fix: 3.0.5 / 3.1.6+
Fix from $2,300 2019-06-03
Bitbucket CRITICAL 9.1
CVE-2019-3397EPSS 5%

Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14…

Fix: 5.13.6 / 5.14.4+
Fix from $2,300 2019-06-03
Jira HIGH 8.1
CVE-2019-8443

The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows …

Fix: 7.13.4 / 8.0.4+
Fix from $1,950 2019-05-22
Jira HIGH 7.5
CVE-2019-8442EPSS 60%

The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 befor…

Fix: 7.13.4 / 8.0.4+
Fix from $1,950 2019-05-22
Jira MEDIUM 6.1
CVE-2019-3402EPSS 9%

The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject ar…

Fix: 7.13.3 / 8.1.1+
Fix from $1,600 2019-05-22
Jira MEDIUM 5.3
CVE-2019-3401EPSS 13%

The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate userna…

Fix: 7.13.3 / 8.1.1+
Fix from $1,600 2019-05-22
Jira MEDIUM 5.3
CVE-2019-3403EPSS 53%

The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before versi…

Fix: 7.13.3 / 8.0.4+
Fix from $1,600 2019-05-22
Jira Server MEDIUM 6.1
CVE-2019-3400

The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or Java…

Fix: 7.13.2 / 8.0.2+
Fix from $1,600 2019-05-03
Jira MEDIUM 6.1
CVE-2018-20824EPSS 38%

The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting…

Fix: 7.13.1+
Fix from $1,600 2019-05-03
Jira HIGH 7.5
CVE-2019-3399

The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see informatio…

Fix: 7.13.2 / 8.0.2+
Fix from $1,950 2019-04-30
Application Links MEDIUM 5.4
CVE-2018-20239

Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and fro…

Fix: 3.4.3 / 4.7.0+
Fix from $1,600 2019-04-30
Confluence Server HIGH 8.8
CVE-2019-3398 KEVEPSS 97%

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to …

Fix: 6.6.13 / 6.12.4+
Fix from $1,950 2019-04-18
Application Links HIGH 8.7
CVE-2017-18111

The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version …

Fix: 5.0.10 / 5.1.3+
Fix from $1,950 2019-03-29
Crowd HIGH 8.1
CVE-2017-18105

The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have prev…

Fix: 3.0.2 / 3.1.1+
Fix from $1,950 2019-03-29
Crowd HIGH 7.5
CVE-2017-18106

The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or…

Fix: 2.9.1+
Fix from $1,950 2019-03-29
Crowd HIGH 7.2
CVE-2017-18108

The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute…

Fix: 2.10.2+
Fix from $1,950 2019-03-29
Crowd MEDIUM 6.5
CVE-2017-18110

The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attacker…

Fix: 3.0.2+
Fix from $1,600 2019-03-29
Crowd MEDIUM 6.1
CVE-2017-18109

The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect…

Fix: 3.0.2+
Fix from $1,600 2019-03-29
Confluence CRITICAL 9.8
CVE-2019-3395EPSS 7%

The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.…

Fix: 6.6.12 / 6.12.3+
Fix from $2,300 2019-03-25