Vulnerabilities > Atlassian > High

DATE CVE VULNERABILITY TITLE RISK
2019-01-09 CVE-2018-1000423 Insufficiently Protected Credentials vulnerability in Atlassian Crowd2
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
local
low complexity
atlassian CWE-522
7.8
2019-01-09 CVE-2018-1000418 Incorrect Authorization vulnerability in Atlassian Hipchat
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
atlassian CWE-863
8.8
2018-11-05 CVE-2018-13397 Unspecified vulnerability in Atlassian Sourcetree
There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories.
network
low complexity
atlassian
8.8
2018-11-05 CVE-2018-13396 Unspecified vulnerability in Atlassian Sourcetree
There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories.
network
low complexity
atlassian
8.8
2018-10-16 CVE-2018-13399 Incorrect Permission Assignment for Critical Resource vulnerability in Atlassian Fisheye
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
local
low complexity
atlassian CWE-732
7.8
2018-07-24 CVE-2018-13386 Argument Injection or Modification vulnerability in Atlassian Sourcetree
There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories.
network
high complexity
atlassian CWE-88
8.1
2018-07-09 CVE-2018-1000617 Improper Input Validation vulnerability in Atlassian Floodlight Controller
Atlassian Floodlight Atlassian Floodlight Controller version 1.2 and earlier versions contains a Denial of Service vulnerability in Forwarding module that can result in Improper type cast in Forwarding module allows remote attackers to cause a DoS(thread crash)..
network
low complexity
atlassian CWE-20
7.5
2018-05-16 CVE-2018-5231 Unspecified vulnerability in Atlassian Jira
The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to perform a denial of service attack via sending requests to it.
network
low complexity
atlassian
7.5
2018-04-25 CVE-2018-5226 Unspecified vulnerability in Atlassian Sourcetree
There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted.
network
low complexity
atlassian
8.8
2018-04-04 CVE-2017-18096 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Application Links
The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative rights to access the content of internal network resources via a Server Side Request Forgery (SSRF) by creating an OAuth application link to a location they control and then redirecting access from the linked location's OAuth status rest resource to an internal location.
network
low complexity
atlassian CWE-918
7.2