VYPR

Fisheye

by Atlassian

CVEs (51)

  • CVE-2012-2926CriMay 22, 2012
    risk 0.67cvss 9.1epss 0.67

    Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3…

  • CVE-2017-16861CriFeb 1, 2018
    risk 0.64cvss 9.8epss 0.02

    It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. An attacker who can access the web interface of Fisheye or Crucible or who hosts a website that a user who can access the web interface of Fisheye or…

  • CVE-2017-14591CriNov 29, 2017
    risk 0.59cvss 9.0epss 0.02

    Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.

  • CVE-2017-9511HigAug 24, 2017
    risk 0.49cvss 7.5epss 0.03

    The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system.

  • CVE-2017-9512HigAug 24, 2017
    risk 0.49cvss 7.5epss 0.02

    The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.

  • CVE-2018-5223HigMar 29, 2018
    risk 0.47cvss 7.2epss 0.02

    Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repository in Fisheye or Crucible can execute code of their choice…

  • CVE-2018-13398MedSep 18, 2018
    risk 0.42cvss 6.5epss 0.01

    The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.

  • CVE-2017-16859MedJun 28, 2018
    risk 0.42cvss 6.5epss 0.03

    The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability…

  • CVE-2018-13392MedAug 13, 2018
    risk 0.40cvss 6.1epss 0.02

    Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.

  • CVE-2018-5228MedApr 24, 2018
    risk 0.40cvss 6.1epss 0.01

    The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.

  • CVE-2017-18090MedFeb 16, 2018
    risk 0.40cvss 6.1epss 0.01

    Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author.

  • CVE-2017-14588MedOct 11, 2017
    risk 0.40cvss 6.1epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.

  • CVE-2018-13388MedJul 10, 2018
    risk 0.35cvss 5.4epss 0.01

    The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.

  • CVE-2017-18034MedFeb 2, 2018
    risk 0.35cvss 5.4epss 0.01

    The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in via a specially…

  • CVE-2017-14587MedOct 11, 2017
    risk 0.35cvss 5.4epss 0.01

    The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.

  • CVE-2017-9510MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.

  • CVE-2017-9509MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.

  • CVE-2017-9508MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.

  • CVE-2017-9507MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.

  • CVE-2017-18094MedMar 22, 2018
    risk 0.31cvss 4.8epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the base path…

Page 1 of 3