VYPR

Netic User Export

by Atlassian

CVEs (2)

  • CVE-2022-42977HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g., an SSH private key) to be…

  • CVE-2022-38367MedSep 5, 2022
    risk 0.34cvss 5.3epss 0.00

    The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.