Vulnerabilities > Atlassian

DATE CVE VULNERABILITY TITLE RISK
2020-11-25 CVE-2020-14191 Missing Authorization vulnerability in Atlassian Crucible
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets.
network
low complexity
atlassian CWE-862
5.0
2020-11-09 CVE-2020-14189 Unspecified vulnerability in Atlassian Jira Comment
The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment.
network
low complexity
atlassian
7.5
2020-11-09 CVE-2020-14188 Unspecified vulnerability in Atlassian Jira Create
The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue.
network
low complexity
atlassian
7.5
2020-10-15 CVE-2020-14185 Missing Authorization vulnerability in Atlassian Jira
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource.
network
low complexity
atlassian CWE-862
5.0
2020-10-12 CVE-2020-14184 Cross-site Scripting vulnerability in Atlassian Jira
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files.
network
atlassian CWE-79
3.5
2020-10-06 CVE-2020-14183 Information Exposure vulnerability in Atlassian Jira
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers.
network
low complexity
atlassian CWE-200
4.0
2020-10-01 CVE-2019-20903 Cross-site Scripting vulnerability in Atlassian Editor-Core
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
network
low complexity
atlassian CWE-79
5.4
2020-09-21 CVE-2020-14180 Information Exposure vulnerability in Atlassian Jira Service Desk
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource.
network
low complexity
atlassian CWE-200
4.0
2020-09-21 CVE-2020-14179 Unspecified vulnerability in Atlassian Jira Server
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint.
network
low complexity
atlassian
5.0
2020-09-21 CVE-2020-14177 Unspecified vulnerability in Atlassian Jira Server
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching.
network
low complexity
atlassian
4.0