Vulnerabilities > Atlassian > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-01-09 | CVE-2018-1000418 | Incorrect Authorization vulnerability in Atlassian Hipchat An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | 8.8 |
2018-07-24 | CVE-2018-13385 | Argument Injection or Modification vulnerability in Atlassian Sourcetree There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. | 7.5 |
2018-02-01 | CVE-2017-16861 | Unspecified vulnerability in Atlassian Crucible and Fisheye It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. | 7.5 |
2017-11-27 | CVE-2017-14586 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Atlassian Hipchat The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. | 7.5 |
2017-04-10 | CVE-2017-5983 | Deserialization of Untrusted Data vulnerability in Atlassian Jira The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object. | 7.5 |
2016-12-09 | CVE-2016-6496 | Improper Input Validation vulnerability in Atlassian Crowd The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning. | 7.5 |
2016-08-02 | CVE-2016-5229 | Improper Access Control vulnerability in Atlassian Bamboo Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization. | 7.5 |
2016-02-08 | CVE-2015-8360 | Improper Input Validation vulnerability in Atlassian Bamboo An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port. | 7.5 |
2016-02-08 | CVE-2014-9757 | Improper Input Validation vulnerability in Atlassian Bamboo The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message. | 7.5 |
2008-01-03 | CVE-2007-6619 | Permissions, Privileges, and Access Controls vulnerability in Atlassian Jira The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows remote attackers to change the default language. | 7.5 |