Vulnerabilities > Atlassian > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-25 CVE-2023-22504 Unrestricted Upload of File with Dangerous Type vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
network
low complexity
atlassian CWE-434
6.5
2023-05-01 CVE-2023-22503 Unspecified vulnerability in Atlassian Confluence Data Center
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space.
network
low complexity
atlassian
5.3
2022-10-14 CVE-2022-36802 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Jira Align
The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery.
network
low complexity
atlassian CWE-918
4.9
2022-08-10 CVE-2022-36801 Cross-site Scripting vulnerability in Atlassian Jira Data Center
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint.
network
low complexity
atlassian CWE-79
6.1
2022-08-03 CVE-2022-36800 Unspecified vulnerability in Atlassian Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint.
network
low complexity
atlassian
4.3
2022-07-26 CVE-2021-43959 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Jira Service Desk and Jira Service Management
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight.
network
low complexity
atlassian CWE-918
5.7
2022-07-26 CVE-2020-36290 Cross-site Scripting vulnerability in Atlassian Confluence Data Center and Confluence Server
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.
network
low complexity
atlassian CWE-79
5.4
2022-06-30 CVE-2022-26135 Server-Side Request Forgery (SSRF) vulnerability in Atlassian products
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint.
network
low complexity
atlassian CWE-918
6.5
2022-03-16 CVE-2021-43955 Unspecified vulnerability in Atlassian Crucible
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.
network
low complexity
atlassian
4.3
2022-03-16 CVE-2021-43956 Unspecified vulnerability in Atlassian Crucible
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
network
low complexity
atlassian
6.1