Vulnerabilities > Atlassian

DATE CVE VULNERABILITY TITLE RISK
2020-03-17 CVE-2019-20105 Missing Authentication for Critical Function vulnerability in Atlassian Application Links
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.
network
low complexity
atlassian CWE-306
4.9
2020-02-13 CVE-2012-1500 Cross-site Scripting vulnerability in Atlassian Greenhopper and Jira
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.
network
low complexity
atlassian CWE-79
5.4
2020-02-12 CVE-2019-20100 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira
The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF).
network
low complexity
atlassian CWE-352
4.7
2020-02-12 CVE-2019-20099 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF).
network
low complexity
atlassian CWE-352
4.3
2020-02-12 CVE-2019-20098 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF).
network
low complexity
atlassian CWE-352
4.3
2020-02-06 CVE-2019-20406 Uncontrolled Search Path Element vulnerability in Atlassian Confluence
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.
local
low complexity
atlassian CWE-427
7.8
2020-02-06 CVE-2019-20405 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
4.3
2020-02-06 CVE-2019-20404 Unspecified vulnerability in Atlassian Jira Data Center and Jira Server
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
network
low complexity
atlassian
4.3
2020-02-06 CVE-2019-20403 Unspecified vulnerability in Atlassian Jira Server
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an information disclosure vulnerability.
network
low complexity
atlassian
5.3
2020-02-06 CVE-2019-20402 Unspecified vulnerability in Atlassian Jira
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
network
low complexity
atlassian
4.9