Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2020-36286 The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.… Data Center 8.5.13 / 8.13.5+ Fix from $1,6002021-04-01 HIGH 7.2 CVE-2021-26070 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via… Data Center 8.13.3 / 8.14.1+ Fix from $1,9502021-03-22 MEDIUM 5.3 CVE-2021-26069 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project k… Data Center 8.5.11 / 8.13.3+ Fix from $1,6002021-03-22 MEDIUM 5.3 CVE-2020-36240 The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to … Crowd 4.0.4 / 4.1.2+ Fix from $1,6002021-03-01 HIGH 8.8 CVE-2021-26068 An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via … Jira Server For Slack 2.0.15+ Fix from $1,9502021-02-22 MEDIUM 5.3 CVE-2020-29448 The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and… Confluence Data Center 6.13.18 / 7.4.6+ Fix from $1,6002021-02-22 MEDIUM 5.3 CVE-2020-29453EPSS 23% The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 bef… Data Center 8.5.11 / 8.13.3+ Fix from $1,6002021-02-22 MEDIUM 5.0 CVE-2020-36232 The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, f… Atlassian Gadgets 4.2.37 / 4.3.2.4+ Fix from $1,6002021-02-22 HIGH 8.8 CVE-2020-12873 An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a w… Alfresco Enterprise Content Management 6.2.1+ Fix from $1,9502021-02-19 HIGH 7.8 CVE-2020-36233 The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before… Bitbucket 6.10.9 / 7.6.4+ Fix from $1,9502021-02-18 MEDIUM 6.1 CVE-2020-36236 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (… Jira 8.5.11 / 8.13.3+ Fix from $1,6002021-02-15 MEDIUM 5.3 CVE-2020-36235 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an In… Jira 8.13.2 / 8.14.1+ Fix from $1,6002021-02-15 MEDIUM 5.3 CVE-2020-36237 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Dis… Data Center 8.15.0+ Fix from $1,6002021-02-15 MEDIUM 5.3 CVE-2021-26067 Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory … Bamboo 7.2.2+ Fix from $1,6002021-01-28 MEDIUM 6.5 CVE-2020-29450 Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Serv… Confluence Data Center 7.2.0+ Fix from $1,6002021-01-19 MEDIUM 5.3 CVE-2020-29446 Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulner… Crucible 4.8.5+ Fix from $1,6002021-01-18 MEDIUM 5.4 CVE-2020-14193 Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF… Automation For Jira 7.1.15+ Fix from $1,6002020-11-30 HIGH 7.5 CVE-2020-14190 Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affec… Crucible 4.8.4+ Fix from $1,9502020-11-25 HIGH 7.5 CVE-2020-14191 Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnera… Crucible 4.8.4+ Fix from $1,9502020-11-25 CRITICAL 9.8 CVE-2020-14188 The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in th… Jira Create 2.0.1+ Fix from $2,3002020-11-09 CRITICAL 9.8 CVE-2020-14189 The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the c… Jira Comment 2.0.2+ Fix from $2,3002020-11-09 MEDIUM 5.3 CVE-2020-14185 Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOper… Jira 7.13.18 / 8.5.9+ Fix from $1,6002020-10-15 MEDIUM 5.4 CVE-2020-14184 Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerabili… Jira 8.5.9 / 8.12.3+ Fix from $1,6002020-10-12 HIGH 7.5 CVE-2019-20902 Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.… Crowd 3.4.6 / 3.5.1+ Fix from $1,9502020-10-01 MEDIUM 5.4 CVE-2019-20903 The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a C… Editor Core 113.1.5+ Fix from $1,6002020-10-01 MEDIUM 6.5 CVE-2020-14177 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial o… Jira Server 7.13.16 / 8.5.7+ Fix from $1,6002020-09-21 MEDIUM 5.3 CVE-2020-14179EPSS 76% Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names vi… Jira Data Center 8.5.8 / 8.11.1+ Fix from $1,6002020-09-21 MEDIUM 5.3 CVE-2020-14181EPSS 100% Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabili… Data Center 7.13.6 / 8.5.7+ Fix from $1,6002020-09-17 HIGH 7.5 CVE-2020-14178 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerabili… Jira 7.13.7 / 8.5.8+ Fix from $1,9502020-09-01 MEDIUM 6.5 CVE-2017-18112 Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability i… Fisheye 4.8.3+ Fix from $1,6002020-08-05