VYPR

Crucible

by Atlassian

CVEs (53)

  • CVE-2018-5228MedApr 24, 2018
    risk 0.40cvss 6.1epss 0.01

    The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.

  • CVE-2017-14588MedOct 11, 2017
    risk 0.40cvss 6.1epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.

  • CVE-2020-29446MedJan 18, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.

  • CVE-2020-4023MedJun 1, 2020
    risk 0.35cvss 5.4epss 0.01

    The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.

  • CVE-2020-4017MedJun 1, 2020
    risk 0.35cvss 5.3epss 0.01

    The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application links via an information disclosure vulnerability.

  • CVE-2020-4016MedJun 1, 2020
    risk 0.35cvss 5.3epss 0.01

    The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.

  • CVE-2020-4013MedJun 1, 2020
    risk 0.35cvss 5.4epss 0.01

    The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.

  • CVE-2018-20239MedApr 30, 2019
    risk 0.35cvss 5.4epss 0.03

    Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS)…

  • CVE-2018-20241MedFeb 20, 2019
    risk 0.35cvss 5.4epss 0.01

    The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.

  • CVE-2018-13388MedJul 10, 2018
    risk 0.35cvss 5.4epss 0.01

    The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.

  • CVE-2017-18095MedFeb 19, 2018
    risk 0.35cvss 5.3epss 0.01

    The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.

  • CVE-2017-18092MedFeb 19, 2018
    risk 0.35cvss 5.4epss 0.01

    The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of a comment on the snippet.

  • CVE-2017-18089MedFeb 16, 2018
    risk 0.35cvss 5.4epss 0.01

    The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.

  • CVE-2017-18034MedFeb 2, 2018
    risk 0.35cvss 5.4epss 0.01

    The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in via a specially…

  • CVE-2017-14587MedOct 11, 2017
    risk 0.35cvss 5.4epss 0.01

    The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.

  • CVE-2017-9509MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.

  • CVE-2017-9508MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.

  • CVE-2017-9507MedAug 24, 2017
    risk 0.35cvss 5.4epss 0.01

    The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.

  • CVE-2019-15007MedDec 11, 2019
    risk 0.31cvss 4.8epss 0.01

    The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.

  • CVE-2018-20240MedFeb 20, 2019
    risk 0.31cvss 4.8epss 0.01

    The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.