atlassian

468 tracked vulnerabilities.

CVE-2020-4026 MEDIUM
Atlassian Navigator Links < 3.3.23, 4.0.0-4.3.6, 5.0.0, 5.1.0 - Incorrect Authorization in CustomAppsRestResource
Jun 03, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-4023 MEDIUM
Atlassian Crucible and Fisheye < 4.8.2 - Cross-Site Scripting via Committer Filter Parameter
Jun 01, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-4021 MEDIUM
Atlassian Jira < 7.13.16, 8.0.0-8.5.5 - Cross-Site Scripting in XML Export View
Jun 01, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-4020 HIGH
Atlassian Companion App <1.0.0 - RCE
Jun 01, 2020
CVSS 7.2
EPSS 0.01
CVE-2020-4019 HIGH
Atlassian Companion < 1.0.0 - Untrusted Search Path via File Editing Functionality
Jun 01, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-4018 HIGH
Atlassian Crucible and Fisheye < 4.8.1 - Cross-Site Request Forgery in Setup Process
Jun 01, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-4017 MEDIUM
Atlassian Crucible and Fisheye < 4.8.1 - Information Disclosure via Jira Application Links Endpoint
Jun 01, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-4016 MEDIUM
Atlassian Crucible and Fisheye < 4.8.1 - Information Disclosure via Jira Blockers Plugin
Jun 01, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-4015 MEDIUM
Atlassian Crucible and Fisheye < 4.8.1 - Information Disclosure via activeUserFinder Endpoint
Jun 01, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-4014 MEDIUM
Atlassian Fisheye/Crucible <4.8.1 - Auth Bypass
Jun 01, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-4013 MEDIUM
Atlassian Crucible and Fisheye < 4.8.1 - Stored Cross-Site Scripting via Review Objectives
Jun 01, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-9344 MEDIUM NUCLEI
Subversion ALM < 8.8.2 - Reflected Cross-Site Scripting
Mar 20, 2020
CVSS 6.1
EPSS 0.40
CVE-2019-15002 MEDIUM
Atlassian Jira 7.6.4-8.1.0 - Cross-Site Request Forgery via Login Form
Feb 11, 2025
CVSS 4.3
EPSS 0.00
CVE-2019-20101 MEDIUM
Atlassian Jira Server/Data Center <8.13.3 & 8.14.0-8.14.1 - Info Di...
Sep 14, 2021
CVSS 5.3
EPSS 0.02
CVE-2019-20903 MEDIUM
atlaskit/editor-core < 113.1.5 - Cross-Site Scripting via Hyperlink Target Injection
Oct 01, 2020
CVSS 5.4
EPSS 0.00
CVE-2019-20902 HIGH
Crowd <3.4.6, >3.5.0-3.5.1 - Info Disclosure
Oct 01, 2020
CVSS 7.5
EPSS 0.00
CVE-2019-20901 MEDIUM
Jira < 8.5.2 and 8.6.0 - Open Redirect via os_destination Parameter
Jul 13, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-20900 MEDIUM
Atlassian Jira Server and Data Center 8.2.1-8.6.x - Cross-Site Scripting in Add Field Module
Jul 13, 2020
CVSS 4.8
EPSS 0.00
CVE-2019-20899 MEDIUM
Atlassian Jira Server/Data Center <8.5.4 & <8.6.1-8.6.0 - DoS
Jul 13, 2020
CVSS 5.3
EPSS 0.00
CVE-2019-20898 HIGH
Atlassian Jira <8.8.0 - Info Disclosure
Jul 13, 2020
CVSS 7.5
EPSS 0.00
CVE-2019-20897 MEDIUM
Atlassian Jira < 8.5.4, 8.6.0-8.6.2, 8.7.0-8.7.1 - Denial of Service via Avatar Upload
Jul 13, 2020
CVSS 6.5
EPSS 0.01
CVE-2019-20419 HIGH
Atlassian Jira Server and Data Center < 8.5.5 and 8.6.0-8.7.2 - Remote Code Execution via Tomcat DLL Hijacking
Jul 03, 2020
CVSS 7.8
EPSS 0.00
CVE-2019-20418 MEDIUM
Atlassian Jira < 8.8.0 - Application Denial of Service via Wiki Rendering Endpoint
Jul 03, 2020
CVSS 6.5
EPSS 0.00
CVE-2019-20408 MEDIUM
Jira < 8.7.0 - Server-Side Request Forgery via Gadgets MakeRequest Endpoint
Jul 01, 2020
CVSS 5.3
EPSS 0.00
CVE-2019-20416 MEDIUM
Atlassian Jira < 8.3.0 - Cross-Site Scripting in Project Configuration
Jun 30, 2020
CVSS 4.8
EPSS 0.00