Vulnerabilities in Atlassian

408 results
Vexday analysis

Com 13 CVEs confirmadas em exploração ativa pelo CISA KEV de um total de 399 catalogadas, a taxa de exploração do portfólio Atlassian é 7,2 vezes acima da média geral do catálogo, o que indica atenção elevada por parte de agentes maliciosos a vulnerabilidades nesse ecossistema. O tipo de falha mais recorrente é CWE-863 (Autorização Incorreta), sugerindo deficiências estruturais em controles de acesso que tendem a ter impacto amplo em ambientes colaborativos. A CVE mais crítica em exploração ativa, CVE-2021-26084, apresenta EPSS máximo de 1,0 — indicador de probabilidade praticamente certa de exploração em campo —, o que a coloca como prioridade absoluta de remediação para qualquer organização que ainda não tenha aplicado os patches correspondentes. Com 19 vulnerabilidades com PoC pública e 22 de severidade crítica no portfólio total, a superfície de risco permanece significativa e exige monitoramento contínuo.

CVE-2018-5228The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScrEPSS 1.2%CVE-2019-14997The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including theirEPSS 1.2%CVE-2017-16864The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross EPSS 1.2%CVE-2020-14175Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-SEPSS 1.2%CVE-2021-43946Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscrEPSS 1.1%CVE-2018-13404The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 EPSS 1.1%CVE-2021-39121Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projecEPSS 1.1%CVE-2020-4022The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8EPSS 1.1%CVE-2017-18109The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers toEPSS 1.1%CVE-2019-20903The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScripEPSS 1.1%CVE-2019-11589The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before vEPSS 1.1%CVE-2017-18039The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML EPSS 1.1%CVE-2021-26067Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home dEPSS 1.1%CVE-2017-14588Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via aEPSS 1.1%CVE-2019-20102The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before versioEPSS 1.1%CVE-2019-3400The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTMEPSS 1.1%CVE-2020-36232The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4EPSS 1.1%CVE-2021-39116Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of SEPSS 1.1%CVE-2020-36234Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site ScEPSS 1.1%CVE-2019-20414Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scEPSS 1.0%