atlassian records
473 published records for vendor atlassian.
Researcher profile
- Entered KEV
- 13 · 2.7%
- Weaponized
- 19 · 4%
- Pre-auth RCE
- 31
- With a fix record
- 2.3%
- Median publish → KEV
- 65 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')106
- CWE-352 Cross-Site Request Forgery (CSRF)32
- CWE-94 Improper Control of Generation of Code ('Code Injection')22
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')20
- CWE-863 Incorrect Authorization18
- CWE-918 Server-Side Request Forgery (SSRF)18
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
473 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2021-26084Weaponized | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Critical9.8 | KEV | 100.0% | Aug 30, 2021 |
99Now | CVE-2023-22518Weaponized | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Critical9.8 | KEV | 100.0% | Oct 31, 2023 |
99Now | CVE-2022-26134Weaponized | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Critical9.8 | KEV | 100.0% | Jun 3, 2022 |
99Now | CVE-2023-22527Weaponized | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE atlassian · confluence data center · CWE-74 | Critical9.8 | KEV | 100.0% | Jan 16, 2024 |
99Now | CVE-2019-3396Weaponized | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1atlassian · confluence server · CWE-22 | Critical9.8 | KEV | 99.9% | Mar 25, 2019 |
99Now | CVE-2023-22515Weaponized | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknowatlassian · confluence data center · CWE-20 | Critical9.8 | KEV | 99.2% | Oct 4, 2023 |
98Now | CVE-2022-26138Weaponized | The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users gatlassian · questions for confluence · CWE-798 | Critical9.8 | KEV | 98.2% | Jul 20, 2022 |
98Now | CVE-2019-11580Weaponized | Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds.atlassian · crowd | Critical9.8 | KEV | 95.4% | Jun 3, 2019 |
95Now | CVE-2022-36804Weaponized | Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10,atlassian · bitbucket · CWE-78 | High8.8 | KEV | 99.2% | Aug 25, 2022 |
94Now | CVE-2019-3398Weaponized | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.atlassian · confluence server · CWE-22 | High8.8 | KEV | 96.8% | Apr 18, 2019 |
94Now | CVE-2019-11581Weaponized | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail aatlassian · jira server · CWE-74 | Critical9.8 | KEV | 84.6% | Aug 9, 2019 |
81Now | CVE-2021-26086Weaponized | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerabilitatlassian · jira data center · CWE-22 | Medium5.3 | KEV | 100.0% | Aug 15, 2021 |
81Now | CVE-2021-26085Weaponized | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File atlassian · confluence data center · CWE-425 | Medium5.3 | KEV | 99.9% | Aug 2, 2021 |
68This week | CVE-2022-43781Weaponized | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.atlassian · bitbucket · CWE-77 | Critical9.8 | — | 98.1% | Nov 16, 2022 |
65This week | CVE-2022-0540Proof of concept | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP requesatlassian · jira data center · CWE-287 | Critical9.8 | — | 88.1% | Apr 20, 2022 |
61This week | CVE-2024-21683Weaponized | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.atlassian · confluence data center · CWE-94 | High8.8 | — | 88.3% | May 21, 2024 |
60This week | CVE-2022-26133Proof of concept | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6atlassian · bitbucket data center · CWE-502 | Critical9.8 | — | 70.4% | Apr 20, 2022 |
56Plan | CVE-2012-2926Weaponized | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 beforatlassian · bamboo | Critical9.1 | — | 66.3% | May 22, 2012 |
54Plan | CVE-2019-8451Proof of concept | The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal netatlassian · jira server · CWE-918 | Medium6.5 | — | 94.5% | Sep 11, 2019 |
54Plan | CVE-2020-36239No exploit | Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 batlassian · jira data center · CWE-862 | Critical9.8 | — | 49.8% | Jul 29, 2021 |
51Plan | CVE-2020-14181Weaponized | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vuatlassian · data center · CWE-200 | Medium5.3 | — | 99.6% | Sep 16, 2020 |
51Plan | CVE-2020-36289Proof of concept | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vuatlassian · data center · CWE-863 | Medium5.3 | — | 99.2% | May 12, 2021 |
48Plan | CVE-2019-8442Proof of concept | The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.atlassian · jira | High7.5 | — | 59.8% | May 22, 2019 |
47Plan | CVE-2022-26135Proof of concept | A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the siatlassian · jira data center · CWE-918 | Medium6.5 | — | 71.6% | Jun 30, 2022 |
46Plan | CVE-2019-8449Proof of concept | The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an informationatlassian · jira · CWE-306 | Medium5.3 | — | 84.8% | Sep 11, 2019 |
- CVE-2021-2608499Now
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerAug 30, 2021
- CVE-2023-2251899Now
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerOct 31, 2023
- CVE-2022-2613499Now
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerJun 3, 2022
- CVE-2023-2252799Now
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerJan 16, 2024
- CVE-2019-339699Now
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence serverMar 25, 2019
- CVE-2023-2251599Now
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow
CriticalCVSS 9.8KEVWeaponizedEPSS 99%atlassian · confluence data centerOct 4, 2023
- CVE-2022-2613898Now
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users g
CriticalCVSS 9.8KEVWeaponizedEPSS 98%atlassian · questions for confluenceJul 20, 2022
- CVE-2019-1158098Now
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds.
CriticalCVSS 9.8KEVWeaponizedEPSS 95%atlassian · crowdJun 3, 2019
- CVE-2022-3680495Now
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10,
HighCVSS 8.8KEVWeaponizedEPSS 99%atlassian · bitbucketAug 25, 2022
- CVE-2019-339894Now
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.
HighCVSS 8.8KEVWeaponizedEPSS 97%atlassian · confluence serverApr 18, 2019
- CVE-2019-1158194Now
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a
CriticalCVSS 9.8KEVWeaponizedEPSS 85%atlassian · jira serverAug 9, 2019
- CVE-2021-2608681Now
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerabilit
MediumCVSS 5.3KEVWeaponizedEPSS 100%atlassian · jira data centerAug 15, 2021
- CVE-2021-2608581Now
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File
MediumCVSS 5.3KEVWeaponizedEPSS 100%atlassian · confluence data centerAug 2, 2021
- CVE-2022-4378168This week
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.
CriticalCVSS 9.8WeaponizedEPSS 98%atlassian · bitbucketNov 16, 2022
- CVE-2022-054065This week
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP reques
CriticalCVSS 9.8Proof of conceptEPSS 88%atlassian · jira data centerApr 20, 2022
- CVE-2024-2168361This week
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
HighCVSS 8.8WeaponizedEPSS 88%atlassian · confluence data centerMay 21, 2024
- CVE-2022-2613360This week
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6
CriticalCVSS 9.8Proof of conceptEPSS 70%atlassian · bitbucket data centerApr 20, 2022
- CVE-2012-292656Plan
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 befor
CriticalCVSS 9.1WeaponizedEPSS 66%atlassian · bambooMay 22, 2012
- CVE-2019-845154Plan
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal net
MediumCVSS 6.5Proof of conceptEPSS 94%atlassian · jira serverSep 11, 2019
- CVE-2020-3623954Plan
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 b
CriticalCVSS 9.8No exploitEPSS 50%atlassian · jira data centerJul 29, 2021
- CVE-2020-1418151Plan
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vu
MediumCVSS 5.3WeaponizedEPSS 100%atlassian · data centerSep 16, 2020
- CVE-2020-3628951Plan
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vu
MediumCVSS 5.3Proof of conceptEPSS 99%atlassian · data centerMay 12, 2021
- CVE-2019-844248Plan
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.
HighCVSS 7.5Proof of conceptEPSS 60%atlassian · jiraMay 22, 2019
- CVE-2022-2613547Plan
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the si
MediumCVSS 6.5Proof of conceptEPSS 72%atlassian · jira data centerJun 30, 2022
- CVE-2019-844946Plan
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information
MediumCVSS 5.3Proof of conceptEPSS 85%atlassian · jiraSep 11, 2019