Vulnerabilities in Atlassian

408 results
Vexday analysis

Com 13 CVEs confirmadas em exploração ativa pelo CISA KEV de um total de 399 catalogadas, a taxa de exploração do portfólio Atlassian é 7,2 vezes acima da média geral do catálogo, o que indica atenção elevada por parte de agentes maliciosos a vulnerabilidades nesse ecossistema. O tipo de falha mais recorrente é CWE-863 (Autorização Incorreta), sugerindo deficiências estruturais em controles de acesso que tendem a ter impacto amplo em ambientes colaborativos. A CVE mais crítica em exploração ativa, CVE-2021-26084, apresenta EPSS máximo de 1,0 — indicador de probabilidade praticamente certa de exploração em campo —, o que a coloca como prioridade absoluta de remediação para qualquer organização que ainda não tenha aplicado os patches correspondentes. Com 19 vulnerabilidades com PoC pública e 22 de severidade crítica no portfólio total, a superfície de risco permanece significativa e exige monitoramento contínuo.

CVE-2020-4027Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass vEPSS 1.5%CVE-2018-20238Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authentEPSS 1.5%CVE-2024-21673HIGHThis High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. RemoteEPSS 1.5%CVE-2019-11583The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnEPSS 1.5%CVE-2019-20105The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, fEPSS 1.5%CVE-2019-20403The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or nEPSS 1.5%CVE-2021-43958CRITICALVarious rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest rEPSS 1.5%CVE-2018-5226There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An atEPSS 1.5%CVE-2018-13387The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 EPSS 1.5%CVE-2020-4029The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2EPSS 1.4%CVE-2017-18038The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrEPSS 1.4%CVE-2018-13400Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before EPSS 1.4%CVE-2017-18105The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who EPSS 1.4%CVE-2021-39118MEDIUMAffected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an eEPSS 1.4%CVE-2020-36286The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from vEPSS 1.4%CVE-2021-39125MEDIUMAffected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumerEPSS 1.4%CVE-2021-39122MEDIUMAffected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information DisclosEPSS 1.4%CVE-2019-20101MEDIUMAffected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access ContEPSS 1.4%CVE-2024-21672HIGHThis High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote CEPSS 1.4%CVE-2018-13401The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before versEPSS 1.4%