Vulnerabilidades en Atlassian

399 resultados
CVE-2021-43946Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscrEPSS 1.1%CVE-2020-29446Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOEPSS 1.1%CVE-2018-13404The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 EPSS 1.1%CVE-2020-4022The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8EPSS 1.1%CVE-2017-18039The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML EPSS 1.1%CVE-2017-18109The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers toEPSS 1.1%CVE-2019-20903The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScripEPSS 1.1%CVE-2017-18101Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.EPSS 1.1%CVE-2019-11589The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before vEPSS 1.1%CVE-2021-26067Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home dEPSS 1.1%CVE-2021-39121Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projecEPSS 1.1%CVE-2017-14588Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via aEPSS 1.1%CVE-2019-20102The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before versioEPSS 1.1%CVE-2019-3400The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTMEPSS 1.1%CVE-2017-18095The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackerEPSS 1.1%CVE-2019-20414Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scEPSS 1.0%CVE-2017-9514Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restricEPSS 1.0%CVE-2017-14594The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackeEPSS 1.0%CVE-2021-39116Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of SEPSS 1.0%CVE-2019-20418Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an ApplicEPSS 1.0%