Skip to content
Noroxi

atlassian records

473 published records for vendor atlassian.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

473 records
  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerAug 30, 2021

  • All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerOct 31, 2023

  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerJun 3, 2022

  • A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerJan 16, 2024

  • The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence serverMar 25, 2019

  • Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    atlassian · confluence data centerOct 4, 2023

  • The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users g

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    atlassian · questions for confluenceJul 20, 2022

  • Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds.

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    atlassian · crowdJun 3, 2019

  • Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10,

    HighCVSS 8.8KEVWeaponizedEPSS 99%

    atlassian · bitbucketAug 25, 2022

  • Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.

    HighCVSS 8.8KEVWeaponizedEPSS 97%

    atlassian · confluence serverApr 18, 2019

  • There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a

    CriticalCVSS 9.8KEVWeaponizedEPSS 85%

    atlassian · jira serverAug 9, 2019

  • Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerabilit

    MediumCVSS 5.3KEVWeaponizedEPSS 100%

    atlassian · jira data centerAug 15, 2021

  • Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File

    MediumCVSS 5.3KEVWeaponizedEPSS 100%

    atlassian · confluence data centerAug 2, 2021

  • CVE-2022-43781
    68This week

    There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.

    CriticalCVSS 9.8WeaponizedEPSS 98%

    atlassian · bitbucketNov 16, 2022

  • CVE-2022-0540
    65This week

    A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP reques

    CriticalCVSS 9.8Proof of conceptEPSS 88%

    atlassian · jira data centerApr 20, 2022

  • CVE-2024-21683
    61This week

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.

    HighCVSS 8.8WeaponizedEPSS 88%

    atlassian · confluence data centerMay 21, 2024

  • CVE-2022-26133
    60This week

    SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6

    CriticalCVSS 9.8Proof of conceptEPSS 70%

    atlassian · bitbucket data centerApr 20, 2022

  • Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 befor

    CriticalCVSS 9.1WeaponizedEPSS 66%

    atlassian · bambooMay 22, 2012

  • The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal net

    MediumCVSS 6.5Proof of conceptEPSS 94%

    atlassian · jira serverSep 11, 2019

  • Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 b

    CriticalCVSS 9.8No exploitEPSS 50%

    atlassian · jira data centerJul 29, 2021

  • Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vu

    MediumCVSS 5.3WeaponizedEPSS 100%

    atlassian · data centerSep 16, 2020

  • Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vu

    MediumCVSS 5.3Proof of conceptEPSS 99%

    atlassian · data centerMay 12, 2021

  • The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.

    HighCVSS 7.5Proof of conceptEPSS 60%

    atlassian · jiraMay 22, 2019

  • A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the si

    MediumCVSS 6.5Proof of conceptEPSS 72%

    atlassian · jira data centerJun 30, 2022

  • The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information

    MediumCVSS 5.3Proof of conceptEPSS 85%

    atlassian · jiraSep 11, 2019