İçeriğe atla
Noroxi

atlassian kayıtları

atlassian üreticisine ait 473 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

473 kayıt
  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center30 Ağu 2021

  • All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center31 Eki 2023

  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center3 Haz 2022

  • A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center16 Oca 2024

  • The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence server25 Mar 2019

  • Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknow

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    atlassian · confluence data center4 Eki 2023

  • The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users g

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    atlassian · questions for confluence20 Tem 2022

  • Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95

    atlassian · crowd3 Haz 2019

  • Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10,

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99

    atlassian · bitbucket25 Ağu 2022

  • Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %97

    atlassian · confluence server18 Nis 2019

  • There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %85

    atlassian · jira server9 Ağu 2019

  • Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerabilit

    OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %100

    atlassian · jira data center15 Ağu 2021

  • Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File

    OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center2 Ağu 2021

  • CVE-2022-43781
    68Bu hafta

    There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.

    KritikCVSS 9,8SilahlaştırılmışEPSS %98

    atlassian · bitbucket16 Kas 2022

  • CVE-2022-0540
    65Bu hafta

    A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP reques

    KritikCVSS 9,8Kavram kanıtıEPSS %88

    atlassian · jira data center20 Nis 2022

  • CVE-2024-21683
    61Bu hafta

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %88

    atlassian · confluence data center21 May 2024

  • CVE-2022-26133
    60Bu hafta

    SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6

    KritikCVSS 9,8Kavram kanıtıEPSS %70

    atlassian · bitbucket data center20 Nis 2022

  • CVE-2012-2926
    56Planlayın

    Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 befor

    KritikCVSS 9,1SilahlaştırılmışEPSS %66

    atlassian · bamboo22 May 2012

  • CVE-2019-8451
    54Planlayın

    The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal net

    OrtaCVSS 6,5Kavram kanıtıEPSS %94

    atlassian · jira server11 Eyl 2019

  • CVE-2020-36239
    54Planlayın

    Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 b

    KritikCVSS 9,8İstismar yokEPSS %50

    atlassian · jira data center29 Tem 2021

  • CVE-2020-14181
    51Planlayın

    Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vu

    OrtaCVSS 5,3SilahlaştırılmışEPSS %100

    atlassian · data center16 Eyl 2020

  • CVE-2020-36289
    51Planlayın

    Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vu

    OrtaCVSS 5,3Kavram kanıtıEPSS %99

    atlassian · data center12 May 2021

  • CVE-2019-8442
    48Planlayın

    The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.

    YüksekCVSS 7,5Kavram kanıtıEPSS %60

    atlassian · jira22 May 2019

  • CVE-2022-26135
    47Planlayın

    A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the si

    OrtaCVSS 6,5Kavram kanıtıEPSS %72

    atlassian · jira data center30 Haz 2022

  • CVE-2019-8449
    46Planlayın

    The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information

    OrtaCVSS 5,3Kavram kanıtıEPSS %85

    atlassian · jira11 Eyl 2019