Vulnerabilities > Atlassian > Application Links > 5.3.6

DATE CVE VULNERABILITY TITLE RISK
2020-03-17 CVE-2019-20105 Missing Authentication for Critical Function vulnerability in Atlassian Application Links
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.
network
low complexity
atlassian CWE-306
4.0
2019-12-17 CVE-2019-15011 Incorrect Default Permissions vulnerability in Atlassian Application Links
The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check.
network
low complexity
atlassian CWE-276
4.0
2018-04-10 CVE-2018-5227 Cross-site Scripting vulnerability in Atlassian Application Links
Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link.
network
atlassian CWE-79
3.5