Vulnerabilities > Atlassian > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-30 CVE-2020-18685 Improper Input Validation vulnerability in Atlassian Floodlight
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP or UDP ports, or group or table IDs.
network
low complexity
atlassian CWE-20
7.5
2021-08-02 CVE-2021-37843 Missing Authentication for Critical Function vulnerability in Atlassian Saml Single Sign ON
The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided).
network
low complexity
atlassian CWE-306
7.5
2021-07-29 CVE-2020-36239 Missing Authentication for Critical Function vulnerability in Atlassian products
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability.
network
low complexity
atlassian CWE-306
7.5
2021-04-16 CVE-2021-26073 Improper Authentication vulnerability in Atlassian Connect Express
Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps.
network
low complexity
atlassian CWE-287
7.7
2020-11-09 CVE-2020-14189 Unspecified vulnerability in Atlassian Jira Comment
The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment.
network
low complexity
atlassian
7.5
2020-11-09 CVE-2020-14188 Unspecified vulnerability in Atlassian Jira Create
The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue.
network
low complexity
atlassian
7.5
2020-07-03 CVE-2020-14172 Deserialization of Untrusted Data vulnerability in Atlassian Jira and Jira Software Data Center
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented.
network
low complexity
atlassian CWE-502
7.5
2020-06-23 CVE-2019-20409 Injection vulnerability in Atlassian Jira
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
7.5
2019-06-03 CVE-2019-11580 Unspecified vulnerability in Atlassian Crowd
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds.
network
low complexity
atlassian
7.5
2019-03-25 CVE-2019-3395 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Confluence and Confluence Server
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.
network
low complexity
atlassian CWE-918
7.5