Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2017-9512 The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive in… Crucible after 4.4.0 Fix from $1,9502017-08-24 MEDIUM 5.4 CVE-2017-9507 The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaS… Crucible after 4.4.0 Fix from $1,6002017-08-24 MEDIUM 5.4 CVE-2017-9508 Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross si… Crucible Mitigation only Fix from $1,6002017-08-24 MEDIUM 5.4 CVE-2017-9509 The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross… Crucible after 4.4.0 Fix from $1,6002017-08-24 MEDIUM 5.4 CVE-2017-9510 The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cros… Fisheye after 4.4.0 Fix from $1,6002017-08-24 MEDIUM 6.1 CVE-2017-9506EPSS 72% The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote a… Oauth No fix yet Fix from $1,6002017-08-23 HIGH 8.8 CVE-2017-8907 Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and t… Bamboo Mitigation only Fix from $1,9502017-06-14 HIGH 8.8 CVE-2017-8080 Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving im… Hipchat Server after 2.2.3 Fix from $1,9502017-05-05 MEDIUM 5.9 CVE-2017-8058 Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate … Hipchat after 3.16.1 Fix from $1,6002017-05-05 CRITICAL 9.8 CVE-2017-8768EPSS 8% Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS co… Sourcetree after 2.5c Fix from $2,3002017-05-04 HIGH 7.5 CVE-2017-7415 Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource. Confluence Server No fix yet Fix from $1,9502017-04-27 CRITICAL 9.1 CVE-2017-7357 Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a fil… Hipchat Server after 2.2.2 Fix from $2,3002017-04-14 CRITICAL 9.8 CVE-2017-5983EPSS 16% The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers… Jira Mitigation only Fix from $2,3002017-04-10 HIGH 8.8 CVE-2016-4319 Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings. Jira after 7.1.8 Fix from $1,9502017-04-10 MEDIUM 5.4 CVE-2016-4317 Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. Confluence after 5.9.10 Fix from $1,6002017-04-10 MEDIUM 6.1 CVE-2016-6285 Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inj… Jira after 7.2.1 Fix from $1,6002017-01-31 HIGH 7.5 CVE-2016-6668 The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat … Confluence Server No fix yet Fix from $1,9502017-01-23 MEDIUM 6.1 CVE-2016-6283 Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the… Confluence after 5.10.5 Fix from $1,6002017-01-18 CRITICAL 9.8 CVE-2016-6496 The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP att… Crowd after 2.8.4 Fix from $2,3002016-12-09 CRITICAL 9.8 CVE-2016-5229EPSS 7% Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers … Bamboo after 5.11.3 Fix from $2,3002016-08-02 MEDIUM 6.1 CVE-2015-8398 Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the… Confluence after 5.8.16 Fix from $1,6002016-04-11 CRITICAL 9.1 CVE-2015-8361 Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers … Bamboo Patch available Fix from $2,3002016-02-08 CRITICAL 9.8 CVE-2015-8360 An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serializ… Bamboo Patch available Fix from $2,3002016-02-08 CRITICAL 9.8 CVE-2014-9757 The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execu… Bamboo Patch available Fix from $2,3002016-02-08 MEDIUM 6.5 CVE-2015-5603EPSS 59% The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors… Hipchat after 6.29.2 Fix from $1,6002015-09-21 MEDIUM 6.8 CVE-2012-6342 Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication o… Confluence Server No fix yet Fix from $1,6002014-05-13 HIGH 7.5 CVE-2013-3926 Atlassian Crowd 2.6.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to a "symmetric backdoor." NOTE: as of 2… Crowd No fix yet Fix from $1,9502013-07-01 MEDIUM 5.8 CVE-2013-3925 Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to in… Crowd No fix yet Fix from $1,6002013-07-01 CRITICAL 9.1 CVE-2012-2926EPSS 67% Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, … Bamboo 2.0.9 / 2.1.2+ Fix from $2,3002012-05-22 MEDIUM 6.4 CVE-2012-2928 The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-part… Jira after 5.0.0 Fix from $1,6002012-05-22