Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2017-18083 The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cros… Confluence 6.4.0+ Fix from $1,6002018-02-02 HIGH 8.8 CVE-2017-18042 The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via … Bamboo 6.3.1+ Fix from $1,9502018-02-02 MEDIUM 6.5 CVE-2017-18037 The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0… Bitbucket 4.14.11 / 5.0.9+ Fix from $1,6002018-02-02 MEDIUM 6.1 CVE-2017-18039 The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaSc… Jira 7.4.4+ Fix from $1,6002018-02-02 MEDIUM 5.4 CVE-2017-18034 The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to … Crucible 4.5.1+ Fix from $1,6002018-02-02 MEDIUM 5.4 CVE-2017-18040 The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via… Bamboo 6.2+ Fix from $1,6002018-02-02 MEDIUM 5.4 CVE-2017-18041 The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaS… Bamboo 6.2.0+ Fix from $1,6002018-02-02 MEDIUM 5.3 CVE-2017-18038 The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files… Bitbucket 5.6.0+ Fix from $1,6002018-02-02 CRITICAL 9.8 CVE-2017-16861 It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. An attacker who can a… Fisheye 4.4.5 / 4.5.2+ Fix from $2,3002018-02-01 MEDIUM 6.8 CVE-2017-16858 The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an … Crowd 3.1.2+ Fix from $1,6002018-01-31 MEDIUM 5.4 CVE-2017-9513 Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence… Activity Streams 6.3.0+ Fix from $1,6002018-01-29 HIGH 8.8 CVE-2017-14592EPSS 6% Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit … Sourcetree 2.7+ Fix from $1,9502018-01-26 HIGH 8.8 CVE-2017-14593EPSS 6% Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commi… Sourcetree 2.4.7.0+ Fix from $1,9502018-01-26 MEDIUM 6.1 CVE-2017-16863 The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting … Jira 7.5.3+ Fix from $1,6002018-01-18 MEDIUM 6.5 CVE-2017-18033 The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external syste… Jira 7.6.1+ Fix from $1,6002018-01-18 MEDIUM 5.3 CVE-2017-16865 The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server S… Jira 7.6.1+ Fix from $1,6002018-01-17 MEDIUM 6.1 CVE-2017-14594 The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inj… Jira 7.2.12 / 7.6.1+ Fix from $1,6002018-01-12 MEDIUM 6.1 CVE-2017-16864 The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scri… Jira 7.4.2+ Fix from $1,6002018-01-12 CRITICAL 9.6 CVE-2017-14589 It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administra… Bamboo 6.1.6 / 6.2.5+ Fix from $2,3002017-12-13 CRITICAL 9.1 CVE-2017-14590 Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a re… Bamboo 6.1.6 / 6.2.5+ Fix from $2,3002017-12-13 HIGH 8.5 CVE-2017-16857 It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. Th… Bitbucket Auto Unapprove Plugin Mitigation only Fix from $1,9502017-12-05 MEDIUM 6.1 CVE-2017-16856 The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripti… Confluence 6.5.2+ Fix from $1,6002017-12-05 CRITICAL 9.0 CVE-2017-14591 Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial reposit… Crucible 4.4.3+ Fix from $2,3002017-11-29 CRITICAL 9.8 CVE-2017-14586 The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at… Hipchat 4.30+ Fix from $2,3002017-11-27 HIGH 7.2 CVE-2017-14585 A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in… Hipchat Data Center 2.2.6 / 3.1.0+ Fix from $1,9502017-11-27 HIGH 8.8 CVE-2017-9514 Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which c… Bamboo Mitigation only Fix from $1,9502017-10-12 MEDIUM 6.1 CVE-2017-14588 Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross si… Crucible after 4.4.1 Fix from $1,6002017-10-11 MEDIUM 5.4 CVE-2017-14587 The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or … Crucible after 4.4.1 Fix from $1,6002017-10-11 HIGH 8.8 CVE-2015-6576 Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an … Bamboo 5.8.5 / 5.9.7+ Fix from $1,9502017-10-03 HIGH 7.5 CVE-2017-9511 The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a p… Crucible after 4.4.0 Fix from $1,9502017-08-24