Vulnerabilities > Atlassian > High

DATE CVE VULNERABILITY TITLE RISK
2019-03-29 CVE-2017-18106 Improper Authentication vulnerability in Atlassian Crowd
The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another user's session provided they can make their identifier hash collide with another user's session identifier hash.
network
high complexity
atlassian CWE-287
7.5
2019-03-29 CVE-2017-18105 Session Fixation vulnerability in Atlassian Crowd
The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability.
network
high complexity
atlassian CWE-384
8.1
2019-03-08 CVE-2018-20236 Command Injection vulnerability in Atlassian Sourcetree
There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling.
network
low complexity
atlassian CWE-77
8.8
2019-03-08 CVE-2018-20235 Unspecified vulnerability in Atlassian Sourcetree
There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories.
network
low complexity
atlassian
8.8
2019-03-08 CVE-2018-20234 Argument Injection or Modification vulnerability in Atlassian Sourcetree
There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories.
network
low complexity
atlassian CWE-88
8.8
2019-02-13 CVE-2018-20238 Session Fixation vulnerability in Atlassian Crowd
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
network
low complexity
atlassian CWE-384
8.1
2019-01-09 CVE-2018-1000423 Insufficiently Protected Credentials vulnerability in Atlassian Crowd2
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
local
low complexity
atlassian CWE-522
7.8
2019-01-09 CVE-2018-1000418 Incorrect Authorization vulnerability in Atlassian Hipchat
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
atlassian CWE-863
8.8
2018-11-05 CVE-2018-13397 Unspecified vulnerability in Atlassian Sourcetree
There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories.
network
low complexity
atlassian
8.8
2018-11-05 CVE-2018-13396 Unspecified vulnerability in Atlassian Sourcetree
There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories.
network
low complexity
atlassian
8.8