Vulnerabilidades en Atlassian

408 resultados
Análisis Vexday

Com 13 CVEs confirmadas em exploração ativa pelo CISA KEV de um total de 399 catalogadas, a taxa de exploração do portfólio Atlassian é 7,2 vezes acima da média geral do catálogo, o que indica atenção elevada por parte de agentes maliciosos a vulnerabilidades nesse ecossistema. O tipo de falha mais recorrente é CWE-863 (Autorização Incorreta), sugerindo deficiências estruturais em controles de acesso que tendem a ter impacto amplo em ambientes colaborativos. A CVE mais crítica em exploração ativa, CVE-2021-26084, apresenta EPSS máximo de 1,0 — indicador de probabilidade praticamente certa de exploração em campo —, o que a coloca como prioridade absoluta de remediação para qualquer organização que ainda não tenha aplicado os patches correspondentes. Com 19 vulnerabilidades com PoC pública e 22 de severidade crítica no portfólio total, a superfície de risco permanece significativa e exige monitoramento contínuo.

CVE-2019-20409The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gaEPSS 2.5%CVE-2019-20097Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0EPSS 2.5%CVE-2019-20104The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perforEPSS 2.4%CVE-2017-14590Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to crEPSS 2.4%CVE-2020-14189The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary codeEPSS 2.4%CVE-2022-26137HIGHA vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked wEPSS 2.3%CVE-2021-43944HIGHThis issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. AfEPSS 2.3%CVE-2017-14591Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in MercuriaEPSS 2.3%CVE-2017-18108The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights tEPSS 2.3%CVE-2020-14177Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-basedEPSS 2.2%CVE-2018-13385There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission tEPSS 2.2%CVE-2020-29450Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a DeniaEPSS 2.2%CVE-2023-22508HIGHThis High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data CentEPSS 2.2%CVE-2019-20899The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated EPSS 2.1%CVE-2020-14167The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, aEPSS 2.1%CVE-2019-20413Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of SEPSS 2.1%CVE-2018-5223Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system mayEPSS 2.1%CVE-2023-22506HIGHThis High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of BambooEPSS 2.1%CVE-2023-22505HIGHThis High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data CentEPSS 2.1%CVE-2019-3399The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see iEPSS 2.1%