Vulnerabilidades em Atlassian

408 resultados
Análise Vexday

Com 13 CVEs confirmadas em exploração ativa pelo CISA KEV de um total de 399 catalogadas, a taxa de exploração do portfólio Atlassian é 7,2 vezes acima da média geral do catálogo, o que indica atenção elevada por parte de agentes maliciosos a vulnerabilidades nesse ecossistema. O tipo de falha mais recorrente é CWE-863 (Autorização Incorreta), sugerindo deficiências estruturais em controles de acesso que tendem a ter impacto amplo em ambientes colaborativos. A CVE mais crítica em exploração ativa, CVE-2021-26084, apresenta EPSS máximo de 1,0 — indicador de probabilidade praticamente certa de exploração em campo —, o que a coloca como prioridade absoluta de remediação para qualquer organização que ainda não tenha aplicado os patches correspondentes. Com 19 vulnerabilidades com PoC pública e 22 de severidade crítica no portfólio total, a superfície de risco permanece significativa e exige monitoramento contínuo.

CVE-2021-43941—Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPagEPSS 0.6%CVE-2017-18040—The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaSEPSS 0.6%CVE-2017-18041—The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTMLEPSS 0.6%CVE-2017-18094—Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers withEPSS 0.6%CVE-2022-36803HIGHThe MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permissiEPSS 0.6%CVE-2017-18084—The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript vEPSS 0.6%CVE-2018-5227—Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administraEPSS 0.6%CVE-2021-26083—Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8EPSS 0.6%CVE-2019-15007—The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript viEPSS 0.6%CVE-2018-5229—The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to injecEPSS 0.6%CVE-2017-16857—It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the bacEPSS 0.6%CVE-2019-20416—Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scEPSS 0.6%CVE-2017-18034—The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write aEPSS 0.6%CVE-2017-18083—The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript vEPSS 0.6%CVE-2017-18082—The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScriptEPSS 0.6%CVE-2021-43945—Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrarEPSS 0.6%CVE-2026-21570HIGHThis High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0EPSS 0.6%CVE-2020-4018—The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a crossEPSS 0.6%CVE-2017-16858—The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 alEPSS 0.6%CVE-2020-14171—Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requesEPSS 0.6%