atlassian
468 tracked vulnerabilities.
CVE-2017-18087
HIGH
Atlassian Bitbucket Server <5.1.7/<5.2.5/<5.3.3/<5.4.1 - Code Injec...
Feb 15, 2018
CVSS 7.5
EPSS 0.02
CVE-2017-18086
MEDIUM
Atlassian Confluence < 6.4.2 - Cross-Site Scripting via issuesURL Parameter
Feb 02, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18085
MEDIUM
Atlassian Confluence < 6.6.1 - Stored Cross-Site Scripting via View Default Decorator Key Parameter
Feb 02, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18084
MEDIUM
Atlassian Confluence < 6.3.4 - Stored Cross-Site Scripting via Macro Description
Feb 02, 2018
CVSS 4.8
EPSS 0.00
CVE-2017-18083
MEDIUM
Atlassian Confluence < 6.4.0 - Cross-Site Scripting via Uploaded File Contents
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-18082
MEDIUM
Atlassian Bamboo < 6.2.3 - Stored Cross-Site Scripting via Branch Name
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-18081
MEDIUM
Atlassian Bamboo < 6.3.1 - Cross-Site Scripting via CSRF Token Cookie
Feb 02, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18080
HIGH
Atlassian Bamboo < 6.3.1 - Cross-Site Request Forgery via saveConfigureSecurity Resource
Feb 02, 2018
CVSS 8.8
EPSS 0.00
CVE-2017-18042
HIGH
Atlassian Bamboo < 6.3.1 - Cross-Site Request Forgery in User Administration Resource
Feb 02, 2018
CVSS 8.8
EPSS 0.00
CVE-2017-18041
MEDIUM
Atlassian Bamboo < 6.2.0 - Cross-Site Scripting via Release Name
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-18040
MEDIUM
Atlassian Bamboo < 6.2 - Cross-Site Scripting via Release Name
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-18039
MEDIUM
Atlassian Jira 6.2.1-7.4.3 - Cross-Site Scripting via IncomingMailServers messagesThreshold Parameter
Feb 02, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18038
MEDIUM
Atlassian Bitbucket < 5.6.0 - Path Traversal via Default Branch Name
Feb 02, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-18037
MEDIUM
Atlassian Bitbucket Path Traversal via Git Tag Name
Feb 02, 2018
CVSS 6.5
EPSS 0.00
CVE-2017-18036
MEDIUM
Atlassian Bitbucket < 5.3.0 - Server-Side Request Forgery via GitHub Repository Importer
Feb 02, 2018
CVSS 4.3
EPSS 0.00
CVE-2017-18035
MEDIUM
Atlassian Fisheye and Crucible < 4.5.1 - Unauthenticated Information Disclosure via Review Coverage Chart Endpoint
Feb 02, 2018
CVSS 4.3
EPSS 0.00
CVE-2017-18034
MEDIUM
Atlassian Crucible and Fisheye < 4.5.1 - Cross-Site Scripting via Repository Branch Name
Feb 02, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-16861
CRITICAL
Atlassian Fisheye and Crucible < 4.4.5 and 4.5.0-4.5.1 - Remote Code Execution via Double OGNL Evaluation
Feb 01, 2018
CVSS 9.8
EPSS 0.01
CVE-2017-16858
MEDIUM
Atlassian Crowd <3.1.2 - Auth Bypass
Jan 31, 2018
CVSS 6.8
EPSS 0.00
CVE-2017-9513
MEDIUM
Atlassian Activity Streams <6.3.0 - Privilege Escalation
Jan 29, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-14593
HIGH
Sourcetree for Windows <2.4.7.0 - Command Injection
Jan 26, 2018
CVSS 8.8
EPSS 0.02
CVE-2017-14592
HIGH
Sourcetree for macOS <2.7.0 - Command Injection
Jan 26, 2018
CVSS 8.8
EPSS 0.02
CVE-2017-16863
MEDIUM
Jira < 7.5.3 - Stored Cross-Site Scripting via PieChart Gadget Project or Filter Name
Jan 18, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-18033
MEDIUM
Jira < 7.6.1 - Cross-Site Request Forgery in Jira-importers-plugin
Jan 18, 2018
CVSS 6.5
EPSS 0.00
CVE-2017-16865
MEDIUM
Atlassian Jira < 7.6.1 - Server-Side Request Forgery via Trello Importer
Jan 17, 2018
CVSS 5.3
EPSS 0.00
Products
jira 142
jira_server 135
jira_data_center 79
crucible 52
fisheye 52
confluence_server 49
jira_software_data_center 39
data_center 38
confluence_data_center 36
bamboo 24
crowd 24
bitbucket 20
confluence 19
jira_service_management 16
sourcetree 15
jira_align 13
jira_service_desk 12
application_links 7
Atlassian Fisheye and Crucible 5
hipchat 5
agiloft 4
floodlight 4
Bamboo 3
bitbucket_data_center 3
companion 3
hipchat_server 3
questions_for_confluence 3
universal_plugin_manager 3
Atlassian Crucible 2
Bamboo Data Center 2
Quick Filters