Vulnerabilities > Atlassian

DATE CVE VULNERABILITY TITLE RISK
2021-03-01 CVE-2020-36240 Information Exposure vulnerability in Atlassian Crowd
The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
network
low complexity
atlassian CWE-200
5.0
2021-02-22 CVE-2021-26068 Injection vulnerability in Atlassian Jira Server for Slack
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.
network
low complexity
atlassian CWE-74
critical
9.0
2021-02-22 CVE-2020-36232 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Atlassian-Gadgets
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, from version 4.4.0 before 4.4.12, and from version 5.0.0 before 5.0.1 allowed unexpected DNS lookups and requests to arbitrary services as it incorrectly obtained application base url information from the executing http request which could be attacker controlled.
network
low complexity
atlassian CWE-918
4.0
2021-02-22 CVE-2020-29453 Path Traversal vulnerability in Atlassian Data Center, Jira Data Center and Jira Server
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
network
low complexity
atlassian CWE-22
5.0
2021-02-22 CVE-2020-29448 Unspecified vulnerability in Atlassian Confluence Data Center and Confluence Server
The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
network
low complexity
atlassian
5.0
2021-02-19 CVE-2020-12873 Injection vulnerability in Atlassian Alfresco Enterprise Content Management
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1.
network
low complexity
atlassian CWE-74
critical
9.0
2021-02-18 CVE-2020-36233 Incorrect Default Permissions vulnerability in Atlassian Bitbucket
The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
local
low complexity
atlassian CWE-276
4.6
2021-02-15 CVE-2020-29451 Unspecified vulnerability in Atlassian Data Center and Jira
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page.
network
low complexity
atlassian
4.0
2021-02-15 CVE-2020-36237 Information Exposure vulnerability in Atlassian Data Center and Jira
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint.
network
low complexity
atlassian CWE-200
5.0
2021-02-15 CVE-2020-36236 Cross-site Scripting vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints.
network
atlassian CWE-79
4.3