atlassian
468 tracked vulnerabilities.
CVE-2018-13398
MEDIUM
Atlassian Crucible and Fisheye < 4.5.4 - Cross-Site Request Forgery in Administrative Smart-Commits Resource
Sep 18, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-13395
MEDIUM
Atlassian Jira < 7.6.8, 7.7.0-7.7.5, 7.8.0-7.8.5, 7.9.0-7.9.3, 7.10.0-7.10.3 - Cross-Site Scripting in Epic Colour Field
Aug 28, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-13391
MEDIUM
Atlassian Jira < 7.6.8, 7.7.0-7.7.4, 7.8.0-7.8.4, 7.9.0-7.9.2, 7.10.0-7.10.2, 7.11.0-7.11.1 - Email Address Exposure
Aug 28, 2018
CVSS 5.3
EPSS 0.00
CVE-2018-13394
MEDIUM
Atlassian Questions for Confluence < 2.6.6 - Cross-Site Request Forgery via acceptAnswer Resource
Aug 15, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-13393
MEDIUM
Atlassian Questions for Confluence < 2.6.6 - Cross-Site Request Forgery via convertCommentToAnswer
Aug 15, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-13392
MEDIUM
Atlassian Crucible and Fisheye < 4.6.0 - Cross-Site Scripting via Linked Issue Keys
Aug 13, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-13390
MEDIUM
cloudtoken 0.1.1-0.1.23 - Unauthenticated AWS Credential Exposure via Network Daemon Access
Aug 10, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-13386
HIGH
Sourcetree for Windows <2.6.9 - Command Injection
Jul 24, 2018
CVSS 8.1
EPSS 0.00
CVE-2018-13385
CRITICAL
Sourcetree for macOS <2.7.6 - Command Injection
Jul 24, 2018
CVSS 9.8
EPSS 0.00
CVE-2018-5232
MEDIUM
Atlassian Jira <7.6.7, >7.7.0-7.10.1 - XSS
Jul 18, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-5229
MEDIUM
Atlassian Universal Plugin Manager <2.22.9 - XSS
Jul 16, 2018
CVSS 5.4
EPSS 0.00
CVE-2018-13387
MEDIUM
Atlassian JIRA Server <7.6.7, 7.7.0-7.7.4, 7.8.0-7.8.4, 7.9.0-7.9.2, 7.10.0-7.10.1 - Stored XSS via IncomingMailServers
Jul 16, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-13389
MEDIUM
Atlassian Confluence < 6.6.1 - Web Content Spoofing via RDF+XML Attachment
Jul 10, 2018
CVSS 4.7
EPSS 0.00
CVE-2018-13388
MEDIUM
Atlassian Crucible and Fisheye < 4.5.3 - Stored Cross-Site Scripting via Review Attachment
Jul 10, 2018
CVSS 5.4
EPSS 0.00
CVE-2018-1000617
HIGH
Atlassian Floodlight Controller <1.2 - DoS
Jul 09, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-5231
HIGH
Atlassian Jira <7.6.6, <7.7.4, <7.8.4, <7.9.2 - DoS
May 16, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-5230
MEDIUM
NUCLEI
Atlassian Jira <7.6.6, <7.7.0-7.7.4, <7.8.0-7.8.4, <7.9.0-7.9.2 - XSS
May 14, 2018
CVSS 6.1
EPSS 0.23
CVE-2018-5226
HIGH
Sourcetree for Windows <2.5.5.0 - Command Injection
Apr 25, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-5228
MEDIUM
Atlassian Fisheye/Crucible <4.5.3 - XSS
Apr 24, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-5227
MEDIUM
Atlassian Application Links <5.4.4 - XSS
Apr 10, 2018
CVSS 4.8
EPSS 0.00
CVE-2018-5224
HIGH
Bamboo 2.7.0-6.3.2 and 6.4.0 - Authenticated Remote Code Execution via Mercurial Repository URI
Mar 29, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-5223
HIGH
Fisheye/Crucible <4.4.6, <4.5.3 - RCE
Mar 29, 2018
CVSS 7.2
EPSS 0.01
CVE-2018-5225
CRITICAL
Atlassian Bitbucket 4.13.0-5.8.1 - Authenticated Remote Code Execution via Symbolic Link
Mar 22, 2018
CVSS 9.9
EPSS 0.03
CVE-2017-18113
HIGH
Jira Server and Data Center < 8.18.1 - Remote Code Execution via Malicious Workflow Import
Aug 02, 2021
CVSS 8.8
EPSS 0.03
CVE-2017-18112
MEDIUM
Atlassian Fisheye < 4.8.3 - Unauthenticated HTTP Password Exposure via Logging Feature
Aug 05, 2020
CVSS 6.5
EPSS 0.00
Products
jira 142
jira_server 135
jira_data_center 79
crucible 52
fisheye 52
confluence_server 49
jira_software_data_center 39
data_center 38
confluence_data_center 36
bamboo 24
crowd 24
bitbucket 20
confluence 19
jira_service_management 16
sourcetree 15
jira_align 13
jira_service_desk 12
application_links 7
Atlassian Fisheye and Crucible 5
hipchat 5
agiloft 4
floodlight 4
Bamboo 3
bitbucket_data_center 3
companion 3
hipchat_server 3
questions_for_confluence 3
universal_plugin_manager 3
Atlassian Crucible 2
Bamboo Data Center 2
Quick Filters