Vulnerabilidades en Atlassian

408 resultados
Análisis Vexday

Com 13 CVEs confirmadas em exploração ativa pelo CISA KEV de um total de 399 catalogadas, a taxa de exploração do portfólio Atlassian é 7,2 vezes acima da média geral do catálogo, o que indica atenção elevada por parte de agentes maliciosos a vulnerabilidades nesse ecossistema. O tipo de falha mais recorrente é CWE-863 (Autorização Incorreta), sugerindo deficiências estruturais em controles de acesso que tendem a ter impacto amplo em ambientes colaborativos. A CVE mais crítica em exploração ativa, CVE-2021-26084, apresenta EPSS máximo de 1,0 — indicador de probabilidade praticamente certa de exploração em campo —, o que a coloca como prioridade absoluta de remediação para qualquer organização que ainda não tenha aplicado os patches correspondentes. Com 19 vulnerabilidades com PoC pública e 22 de severidade crítica no portfólio total, a superfície de risco permanece significativa e exige monitoramento contínuo.

CVE-2017-18087The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5,EPSS 1.8%CVE-2018-20237Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word exporEPSS 1.7%CVE-2019-15003The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.1EPSS 1.7%CVE-2021-39114HIGHAffected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to exEPSS 1.7%CVE-2020-14168The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 befEPSS 1.7%CVE-2018-13392Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via aEPSS 1.7%CVE-2021-41307HIGHAffected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and EPSS 1.7%CVE-2020-4020The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence SerEPSS 1.7%CVE-2017-8907HIGHAtlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permissEPSS 1.7%CVE-2021-39109HIGHThe renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traEPSS 1.7%CVE-2017-18111The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 beforeEPSS 1.6%CVE-2021-41306HIGHAffected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an EPSS 1.6%CVE-2021-26075The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before EPSS 1.6%CVE-2017-18104The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are aEPSS 1.6%CVE-2021-39123HIGHAffected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability vEPSS 1.6%CVE-2019-15012Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.EPSS 1.6%CVE-2020-36238The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from vEPSS 1.6%CVE-2018-13386There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permissionEPSS 1.6%CVE-2023-22526HIGHThis High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (RemoteEPSS 1.6%CVE-2020-36288The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and froEPSS 1.5%