Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Sourcetree HIGH 8.8
CVE-2024-21697

This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Win…

Mitigation only
Fix from $1,950 2024-11-19
Fisheye MEDIUM 6.1
CVE-2017-18090

Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject a…

Mitigation only
Fix from $1,600 2018-02-16
Bitbucket Auto Unapprove Plugin HIGH 8.5
CVE-2017-16857

It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. Th…

Mitigation only
Fix from $1,950 2017-12-05
Bamboo HIGH 8.8
CVE-2017-9514

Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which c…

Mitigation only
Fix from $1,950 2017-10-12
Crucible MEDIUM 5.4
CVE-2017-9508

Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross si…

Mitigation only
Fix from $1,600 2017-08-24
Oauth MEDIUM 6.1
CVE-2017-9506EPSS 72%

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote a…

No fix yet
Fix from $1,600 2017-08-23
Bamboo HIGH 8.8
CVE-2017-8907

Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and t…

Mitigation only
Fix from $1,950 2017-06-14
Confluence Server HIGH 7.5
CVE-2017-7415

Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.

No fix yet
Fix from $1,950 2017-04-27
Jira CRITICAL 9.8
CVE-2017-5983EPSS 16%

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers…

Mitigation only
Fix from $2,300 2017-04-10
Confluence Server HIGH 7.5
CVE-2016-6668

The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat …

No fix yet
Fix from $1,950 2017-01-23
Confluence Server MEDIUM 6.8
CVE-2012-6342

Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication o…

No fix yet
Fix from $1,600 2014-05-13
Crowd HIGH 7.5
CVE-2013-3926

Atlassian Crowd 2.6.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to a "symmetric backdoor." NOTE: as of 2…

No fix yet
Fix from $1,950 2013-07-01
Crowd MEDIUM 5.8
CVE-2013-3925

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to in…

No fix yet
Fix from $1,600 2013-07-01
Jira MEDIUM 6.8
CVE-2008-6832

Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows remote attackers to hijack the authentication of uns…

No fix yet
Fix from $1,600 2009-06-08
Jira MEDIUM 5.0
CVE-2006-3339

secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-#156 allows remote attackers to obtain sensitive information via unspecified manipulations o…

Mitigation only
Fix from $1,600 2006-07-03