Vulnerabilities > Atlassian > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-07-24 CVE-2018-13385 Argument Injection or Modification vulnerability in Atlassian Sourcetree
There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories.
network
low complexity
atlassian CWE-88
critical
9.8
2018-03-22 CVE-2018-5225 Link Following vulnerability in Atlassian Bitbucket
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.
network
low complexity
atlassian CWE-59
critical
9.9
2018-02-01 CVE-2017-16861 Unspecified vulnerability in Atlassian Fisheye
It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur.
network
low complexity
atlassian
critical
9.8
2017-12-13 CVE-2017-14590 Unspecified vulnerability in Atlassian Bamboo
Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters.
network
low complexity
atlassian
critical
9.1
2017-12-13 CVE-2017-14589 Improper Input Validation vulnerability in Atlassian Bamboo
It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur.
network
low complexity
atlassian CWE-20
critical
9.6
2017-11-29 CVE-2017-14591 Argument Injection or Modification vulnerability in Atlassian Crucible
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
network
high complexity
atlassian CWE-88
critical
9.0
2017-11-27 CVE-2017-14586 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Atlassian Hipchat
The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing.
network
low complexity
atlassian CWE-119
critical
9.8
2017-05-04 CVE-2017-8768 OS Command Injection vulnerability in Atlassian Sourcetree
Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme.
network
low complexity
atlassian CWE-78
critical
9.8
2017-04-14 CVE-2017-7357 Unrestricted Upload of File with Dangerous Type vulnerability in Atlassian Hipchat Server 2.2.0/2.2.1/2.2.2
Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file.
network
low complexity
atlassian CWE-434
critical
9.1
2017-04-10 CVE-2017-5983 Deserialization of Untrusted Data vulnerability in Atlassian Jira
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
network
low complexity
atlassian CWE-502
critical
9.8