VYPR

Vendor CVEs

Atlassian

All CVEs

507 total · sorted by risk
  • CVE-2024-48941MedOct 10, 2024
    risk 0.35cvss 5.4epss 0.00

    The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.

  • CVE-2023-36662MedJun 26, 2023
    risk 0.35cvss 5.4epss 0.00

    The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through…

  • CVE-2023-30453MedJun 16, 2023
    risk 0.35cvss 5.4epss 0.00

    The Teamlead Reminder plugin through 2.6.5 for Jira allows persistent XSS via the message parameter.

  • CVE-2023-33287MedMay 31, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Inline Table Editing application before 3.8.0 for Confluence allows attackers to store and execute arbitrary JavaScript via a crafted payload injected into the tables.

  • CVE-2023-22503MedMay 1, 2023
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This…

  • CVE-2022-44726MedApr 17, 2023
    risk 0.35cvss 5.4epss 0.00

    The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.

  • CVE-2020-36290MedJul 26, 2022
    risk 0.35cvss 5.4epss 0.01

    The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site…

  • CVE-2022-32274MedJul 13, 2022
    risk 0.35cvss 5.4epss 0.01

    The Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to stored XSS via the project name to the creation function.

  • CVE-2022-32567MedJul 7, 2022
    risk 0.35cvss 5.4epss 0.01

    The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function.

  • CVE-2021-41309MedDec 8, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the…

  • CVE-2021-39127MedOct 21, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.

  • CVE-2021-39125MedSep 14, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.

  • CVE-2021-39118MedSep 14, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0.

  • CVE-2019-20101MedSep 14, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist//check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0…

  • CVE-2021-39122MedSep 8, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5,…

  • CVE-2021-39119MedSep 1, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected…

  • CVE-2021-26083MedJul 20, 2021
    risk 0.35cvss 5.4epss 0.01

    Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.

  • CVE-2021-26082MedJul 20, 2021
    risk 0.35cvss 5.4epss 0.01

    The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a stored cross site scripting vulnerability.

  • CVE-2021-26081MedJul 20, 2021
    risk 0.35cvss 5.3epss 0.01

    REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to enumerate usernames via a Sensitive Data Exposure vulnerability in the…

  • CVE-2020-29444MedMay 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.

  • CVE-2020-36287MedApr 9, 2021
    risk 0.35cvss 5.3epss 0.09

    The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions…

  • CVE-2020-36286MedApr 1, 2021
    risk 0.35cvss 5.3epss 0.01

    The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are…

  • CVE-2020-36238MedApr 1, 2021
    risk 0.35cvss 5.3epss 0.02

    The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions…

  • CVE-2021-26069MedMar 22, 2021
    risk 0.35cvss 5.3epss 0.03

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations API endpoint. The affected…

  • CVE-2021-27222MedMar 8, 2021
    risk 0.35cvss 5.4epss 0.01

    In the "Time in Status" app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS.

  • CVE-2020-36240MedMar 1, 2021
    risk 0.35cvss 5.3epss 0.01

    The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

  • CVE-2020-29448MedFeb 22, 2021
    risk 0.35cvss 5.3epss 0.02

    The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories…

  • CVE-2020-36237MedFeb 15, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.

  • CVE-2020-36235MedFeb 15, 2021
    risk 0.35cvss 5.3epss 0.02

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version…

  • CVE-2021-26067MedJan 28, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint. The…

  • CVE-2020-29446MedJan 18, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.

  • CVE-2020-14193MedNov 30, 2020
    risk 0.35cvss 5.4epss 0.01

    Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & /jira/bin directories via a template injection vulnerability in Jira smart values using mustache…

  • CVE-2020-14185MedOct 15, 2020
    risk 0.35cvss 5.3epss 0.02

    Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version…

  • CVE-2020-14184MedOct 12, 2020
    risk 0.35cvss 5.4epss 0.01

    Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected versions are before 8.5.9, from version 8.6.0 before 8.12.3, and from version…

  • CVE-2019-20903MedOct 1, 2020
    risk 0.35cvss 5.4epss 0.01

    The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.

  • CVE-2020-15944MedAug 4, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has…

  • CVE-2020-14175MedJul 24, 2020
    risk 0.35cvss 5.4epss 0.01

    Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before…

  • CVE-2019-20899MedJul 13, 2020
    risk 0.35cvss 5.3epss 0.02

    The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.

  • CVE-2020-14173MedJul 3, 2020
    risk 0.35cvss 5.4epss 0.01

    The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2,…

  • CVE-2020-4024MedJul 1, 2020
    risk 0.35cvss 5.4epss 0.01

    The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a…

  • CVE-2020-14165MedJul 1, 2020
    risk 0.35cvss 5.3epss 0.01

    The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.

  • CVE-2019-20408MedJul 1, 2020
    risk 0.35cvss 5.3epss 0.01

    The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

  • CVE-2019-20414MedJun 29, 2020
    risk 0.35cvss 5.4epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before…

  • CVE-2019-20412MedJun 29, 2020
    risk 0.35cvss 5.3epss 0.02

    The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue…

  • CVE-2020-4028MedJun 23, 2020
    risk 0.35cvss 5.3epss 0.01

    Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure…

  • CVE-2020-4023MedJun 1, 2020
    risk 0.35cvss 5.4epss 0.01

    The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.

  • CVE-2020-4021MedJun 1, 2020
    risk 0.35cvss 5.4epss 0.01

    Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.

  • CVE-2020-4017MedJun 1, 2020
    risk 0.35cvss 5.3epss 0.01

    The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application links via an information disclosure vulnerability.

  • CVE-2020-4016MedJun 1, 2020
    risk 0.35cvss 5.3epss 0.01

    The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.

  • CVE-2020-4013MedJun 1, 2020
    risk 0.35cvss 5.4epss 0.01

    The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.

Page 7 of 11