Записи atlassian
473 опубликованных записей вендора atlassian.
Профиль для исследователя
- Попали в KEV
- 13 · 2,7 %
- С эксплойтом
- 19 · 4 %
- Pre-auth RCE
- 31
- С записью об исправлении
- 2,3 %
- Медиана: публикация → KEV
- 65 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')106
- CWE-352 Cross-Site Request Forgery (CSRF)32
- CWE-94 Improper Control of Generation of Code ('Code Injection')22
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')20
- CWE-863 Incorrect Authorization18
- CWE-918 Server-Side Request Forgery (SSRF)18
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
473 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2021-26084Готовый эксплойт | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Критическая9,8 | KEV | 100,0 % | 30 авг. 2021 г. |
99Срочно | CVE-2023-22518Готовый эксплойт | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Критическая9,8 | KEV | 100,0 % | 31 окт. 2023 г. |
99Срочно | CVE-2022-26134Готовый эксплойт | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Критическая9,8 | KEV | 100,0 % | 3 июн. 2022 г. |
99Срочно | CVE-2023-22527Готовый эксплойт | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE atlassian · confluence data center · CWE-74 | Критическая9,8 | KEV | 100,0 % | 16 янв. 2024 г. |
99Срочно | CVE-2019-3396Готовый эксплойт | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1atlassian · confluence server · CWE-22 | Критическая9,8 | KEV | 99,9 % | 25 мар. 2019 г. |
99Срочно | CVE-2023-22515Готовый эксплойт | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknowatlassian · confluence data center · CWE-20 | Критическая9,8 | KEV | 99,2 % | 4 окт. 2023 г. |
98Срочно | CVE-2022-26138Готовый эксплойт | The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users gatlassian · questions for confluence · CWE-798 | Критическая9,8 | KEV | 98,2 % | 20 июл. 2022 г. |
98Срочно | CVE-2019-11580Готовый эксплойт | Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds.atlassian · crowd | Критическая9,8 | KEV | 95,4 % | 3 июн. 2019 г. |
95Срочно | CVE-2022-36804Готовый эксплойт | Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10,atlassian · bitbucket · CWE-78 | Высокая8,8 | KEV | 99,2 % | 25 авг. 2022 г. |
94Срочно | CVE-2019-3398Готовый эксплойт | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.atlassian · confluence server · CWE-22 | Высокая8,8 | KEV | 96,8 % | 18 апр. 2019 г. |
94Срочно | CVE-2019-11581Готовый эксплойт | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail aatlassian · jira server · CWE-74 | Критическая9,8 | KEV | 84,6 % | 9 авг. 2019 г. |
81Срочно | CVE-2021-26086Готовый эксплойт | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerabilitatlassian · jira data center · CWE-22 | Средняя5,3 | KEV | 100,0 % | 15 авг. 2021 г. |
81Срочно | CVE-2021-26085Готовый эксплойт | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File atlassian · confluence data center · CWE-425 | Средняя5,3 | KEV | 99,9 % | 2 авг. 2021 г. |
68На этой неделе | CVE-2022-43781Готовый эксплойт | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.atlassian · bitbucket · CWE-77 | Критическая9,8 | — | 98,1 % | 16 нояб. 2022 г. |
65На этой неделе | CVE-2022-0540Proof of concept | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP requesatlassian · jira data center · CWE-287 | Критическая9,8 | — | 88,1 % | 20 апр. 2022 г. |
61На этой неделе | CVE-2024-21683Готовый эксплойт | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.atlassian · confluence data center · CWE-94 | Высокая8,8 | — | 88,3 % | 21 мая 2024 г. |
60На этой неделе | CVE-2022-26133Proof of concept | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6atlassian · bitbucket data center · CWE-502 | Критическая9,8 | — | 70,4 % | 20 апр. 2022 г. |
56В плане | CVE-2012-2926Готовый эксплойт | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 beforatlassian · bamboo | Критическая9,1 | — | 66,3 % | 22 мая 2012 г. |
54В плане | CVE-2019-8451Proof of concept | The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal netatlassian · jira server · CWE-918 | Средняя6,5 | — | 94,5 % | 11 сент. 2019 г. |
54В плане | CVE-2020-36239Эксплойта нет | Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 batlassian · jira data center · CWE-862 | Критическая9,8 | — | 49,8 % | 29 июл. 2021 г. |
51В плане | CVE-2020-14181Готовый эксплойт | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vuatlassian · data center · CWE-200 | Средняя5,3 | — | 99,6 % | 16 сент. 2020 г. |
51В плане | CVE-2020-36289Proof of concept | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vuatlassian · data center · CWE-863 | Средняя5,3 | — | 99,2 % | 12 мая 2021 г. |
48В плане | CVE-2019-8442Proof of concept | The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.atlassian · jira | Высокая7,5 | — | 59,8 % | 22 мая 2019 г. |
47В плане | CVE-2022-26135Proof of concept | A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the siatlassian · jira data center · CWE-918 | Средняя6,5 | — | 71,6 % | 30 июн. 2022 г. |
46В плане | CVE-2019-8449Proof of concept | The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an informationatlassian · jira · CWE-306 | Средняя5,3 | — | 84,8 % | 11 сент. 2019 г. |
- CVE-2021-2608499Срочно
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center30 авг. 2021 г.
- CVE-2023-2251899Срочно
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center31 окт. 2023 г.
- CVE-2022-2613499Срочно
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center3 июн. 2022 г.
- CVE-2023-2252799Срочно
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center16 янв. 2024 г.
- CVE-2019-339699Срочно
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence server25 мар. 2019 г.
- CVE-2023-2251599Срочно
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %atlassian · confluence data center4 окт. 2023 г.
- CVE-2022-2613898Срочно
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users g
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %atlassian · questions for confluence20 июл. 2022 г.
- CVE-2019-1158098Срочно
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %atlassian · crowd3 июн. 2019 г.
- CVE-2022-3680495Срочно
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10,
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %atlassian · bitbucket25 авг. 2022 г.
- CVE-2019-339894Срочно
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 97 %atlassian · confluence server18 апр. 2019 г.
- CVE-2019-1158194Срочно
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 85 %atlassian · jira server9 авг. 2019 г.
- CVE-2021-2608681Срочно
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerabilit
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 100 %atlassian · jira data center15 авг. 2021 г.
- CVE-2021-2608581Срочно
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center2 авг. 2021 г.
- CVE-2022-4378168На этой неделе
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.
КритическаяCVSS 9,8Готовый эксплойтEPSS 98 %atlassian · bitbucket16 нояб. 2022 г.
- CVE-2022-054065На этой неделе
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP reques
КритическаяCVSS 9,8Proof of conceptEPSS 88 %atlassian · jira data center20 апр. 2022 г.
- CVE-2024-2168361На этой неделе
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 88 %atlassian · confluence data center21 мая 2024 г.
- CVE-2022-2613360На этой неделе
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6
КритическаяCVSS 9,8Proof of conceptEPSS 70 %atlassian · bitbucket data center20 апр. 2022 г.
- CVE-2012-292656В плане
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 befor
КритическаяCVSS 9,1Готовый эксплойтEPSS 66 %atlassian · bamboo22 мая 2012 г.
- CVE-2019-845154В плане
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal net
СредняяCVSS 6,5Proof of conceptEPSS 94 %atlassian · jira server11 сент. 2019 г.
- CVE-2020-3623954В плане
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 b
КритическаяCVSS 9,8Эксплойта нетEPSS 50 %atlassian · jira data center29 июл. 2021 г.
- CVE-2020-1418151В плане
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vu
СредняяCVSS 5,3Готовый эксплойтEPSS 100 %atlassian · data center16 сент. 2020 г.
- CVE-2020-3628951В плане
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vu
СредняяCVSS 5,3Proof of conceptEPSS 99 %atlassian · data center12 мая 2021 г.
- CVE-2019-844248В плане
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.
ВысокаяCVSS 7,5Proof of conceptEPSS 60 %atlassian · jira22 мая 2019 г.
- CVE-2022-2613547В плане
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the si
СредняяCVSS 6,5Proof of conceptEPSS 72 %atlassian · jira data center30 июн. 2022 г.
- CVE-2019-844946В плане
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information
СредняяCVSS 5,3Proof of conceptEPSS 85 %atlassian · jira11 сент. 2019 г.