Vulnerabilities > Atlassian

DATE CVE VULNERABILITY TITLE RISK
2021-09-01 CVE-2021-39119 Incorrect Authorization vulnerability in Atlassian Data Center and Jira
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature.
network
low complexity
atlassian CWE-863
5.3
2021-09-01 CVE-2021-39109 Path Traversal vulnerability in Atlassian Atlasboard
The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traversal vulnerability.
network
low complexity
atlassian CWE-22
7.5
2021-08-30 CVE-2021-26084 Expression Language Injection vulnerability in Atlassian Confluence Data Center and Confluence Server
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.
network
low complexity
atlassian CWE-917
critical
9.8
2021-08-30 CVE-2021-39111 Cross-site Scripting vulnerability in Atlassian products
The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into a field such as the description field.
network
low complexity
atlassian CWE-79
6.1
2021-08-30 CVE-2021-39113 Insufficient Session Expiration vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature.
network
low complexity
atlassian CWE-613
7.5
2021-08-30 CVE-2021-39117 Cross-site Scripting vulnerability in Atlassian Data Center and Jira
The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field.
network
low complexity
atlassian CWE-79
4.8
2021-08-25 CVE-2021-39112 Open Redirect vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature.
network
low complexity
atlassian CWE-601
4.8
2021-08-16 CVE-2021-26086 Path Traversal vulnerability in Atlassian Jira Data Center and Jira Server
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint.
network
low complexity
atlassian CWE-22
5.3
2021-08-03 CVE-2021-26085 Forced Browsing vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint.
network
low complexity
atlassian CWE-425
5.3
2021-08-02 CVE-2021-37843 Missing Authentication for Critical Function vulnerability in Atlassian Saml Single Sign on
The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided).
network
low complexity
atlassian CWE-306
critical
9.8