Vulnerabilidades en Atlassian

408 resultados
Análisis Vexday

Com 13 CVEs confirmadas em exploração ativa pelo CISA KEV de um total de 399 catalogadas, a taxa de exploração do portfólio Atlassian é 7,2 vezes acima da média geral do catálogo, o que indica atenção elevada por parte de agentes maliciosos a vulnerabilidades nesse ecossistema. O tipo de falha mais recorrente é CWE-863 (Autorização Incorreta), sugerindo deficiências estruturais em controles de acesso que tendem a ter impacto amplo em ambientes colaborativos. A CVE mais crítica em exploração ativa, CVE-2021-26084, apresenta EPSS máximo de 1,0 — indicador de probabilidade praticamente certa de exploração em campo —, o que a coloca como prioridade absoluta de remediação para qualquer organização que ainda não tenha aplicado os patches correspondentes. Com 19 vulnerabilidades com PoC pública e 22 de severidade crítica no portfólio total, a superfície de risco permanece significativa e exige monitoramento contínuo.

CVE-2018-13401The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before versEPSS 1.4%CVE-2026-21571CRITICALThis Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0,EPSS 1.3%CVE-2019-15005The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans anEPSS 1.3%CVE-2020-36236Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site ScEPSS 1.3%CVE-2021-39127MEDIUMAffected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a BrokenEPSS 1.3%CVE-2019-20898Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticateEPSS 1.3%CVE-2017-18037The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from veEPSS 1.3%CVE-2019-20404The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles theyEPSS 1.3%CVE-2021-43957HIGHAffected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IEPSS 1.3%CVE-2021-26080EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version 8.13.6, and from 8.EPSS 1.3%CVE-2020-14183Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's SupportEPSS 1.3%CVE-2020-36240The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attaEPSS 1.3%CVE-2019-14996The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inEPSS 1.3%CVE-2017-9505Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notificaEPSS 1.3%CVE-2020-4017The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 alEPSS 1.2%CVE-2020-4016The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows rEPSS 1.2%CVE-2020-36237Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an InformEPSS 1.2%CVE-2021-26079The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7,EPSS 1.2%CVE-2017-18106The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for anotheEPSS 1.2%CVE-2021-26076The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 befoEPSS 1.2%