atlassian

468 tracked vulnerabilities.

CVE-2017-18087 HIGH
Atlassian Bitbucket Server <5.1.7/<5.2.5/<5.3.3/<5.4.1 - Code Injec...
Feb 15, 2018
CVSS 7.5
EPSS 0.02
CVE-2017-18086 MEDIUM
Atlassian Confluence < 6.4.2 - Cross-Site Scripting via issuesURL Parameter
Feb 02, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18085 MEDIUM
Atlassian Confluence < 6.6.1 - Stored Cross-Site Scripting via View Default Decorator Key Parameter
Feb 02, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18084 MEDIUM
Atlassian Confluence < 6.3.4 - Stored Cross-Site Scripting via Macro Description
Feb 02, 2018
CVSS 4.8
EPSS 0.00
CVE-2017-18083 MEDIUM
Atlassian Confluence < 6.4.0 - Cross-Site Scripting via Uploaded File Contents
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-18082 MEDIUM
Atlassian Bamboo < 6.2.3 - Stored Cross-Site Scripting via Branch Name
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-18081 MEDIUM
Atlassian Bamboo < 6.3.1 - Cross-Site Scripting via CSRF Token Cookie
Feb 02, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18080 HIGH
Atlassian Bamboo < 6.3.1 - Cross-Site Request Forgery via saveConfigureSecurity Resource
Feb 02, 2018
CVSS 8.8
EPSS 0.00
CVE-2017-18042 HIGH
Atlassian Bamboo < 6.3.1 - Cross-Site Request Forgery in User Administration Resource
Feb 02, 2018
CVSS 8.8
EPSS 0.00
CVE-2017-18041 MEDIUM
Atlassian Bamboo < 6.2.0 - Cross-Site Scripting via Release Name
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-18040 MEDIUM
Atlassian Bamboo < 6.2 - Cross-Site Scripting via Release Name
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-18039 MEDIUM
Atlassian Jira 6.2.1-7.4.3 - Cross-Site Scripting via IncomingMailServers messagesThreshold Parameter
Feb 02, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18038 MEDIUM
Atlassian Bitbucket < 5.6.0 - Path Traversal via Default Branch Name
Feb 02, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-18037 MEDIUM
Atlassian Bitbucket Path Traversal via Git Tag Name
Feb 02, 2018
CVSS 6.5
EPSS 0.00
CVE-2017-18036 MEDIUM
Atlassian Bitbucket < 5.3.0 - Server-Side Request Forgery via GitHub Repository Importer
Feb 02, 2018
CVSS 4.3
EPSS 0.00
CVE-2017-18035 MEDIUM
Atlassian Fisheye and Crucible < 4.5.1 - Unauthenticated Information Disclosure via Review Coverage Chart Endpoint
Feb 02, 2018
CVSS 4.3
EPSS 0.00
CVE-2017-18034 MEDIUM
Atlassian Crucible and Fisheye < 4.5.1 - Cross-Site Scripting via Repository Branch Name
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-16861 CRITICAL
Atlassian Fisheye and Crucible < 4.4.5 and 4.5.0-4.5.1 - Remote Code Execution via Double OGNL Evaluation
Feb 01, 2018
CVSS 9.8
EPSS 0.01
CVE-2017-16858 MEDIUM
Atlassian Crowd <3.1.2 - Auth Bypass
Jan 31, 2018
CVSS 6.8
EPSS 0.00
CVE-2017-9513 MEDIUM
Atlassian Activity Streams <6.3.0 - Privilege Escalation
Jan 29, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-14593 HIGH
Sourcetree for Windows <2.4.7.0 - Command Injection
Jan 26, 2018
CVSS 8.8
EPSS 0.02
CVE-2017-14592 HIGH
Sourcetree for macOS <2.7.0 - Command Injection
Jan 26, 2018
CVSS 8.8
EPSS 0.02
CVE-2017-16863 MEDIUM
Jira < 7.5.3 - Stored Cross-Site Scripting via PieChart Gadget Project or Filter Name
Jan 18, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18033 MEDIUM
Jira < 7.6.1 - Cross-Site Request Forgery in Jira-importers-plugin
Jan 18, 2018
CVSS 6.5
EPSS 0.00
CVE-2017-16865 MEDIUM
Atlassian Jira < 7.6.1 - Server-Side Request Forgery via Trello Importer
Jan 17, 2018
CVSS 5.3
EPSS 0.00