Vulnerabilities > Atlassian > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-04-22 CVE-2019-20102 Cross-site Scripting vulnerability in Atlassian Confluence Server
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.
network
low complexity
atlassian CWE-79
6.1
2020-03-20 CVE-2020-9344 Cross-site Scripting vulnerability in Atlassian Subversion Application Lifecycle Management
Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.
network
low complexity
atlassian CWE-79
6.1
2020-03-17 CVE-2019-20407 Missing Authorization vulnerability in Atlassian Jira Data Center and Jira Server
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.
network
low complexity
atlassian CWE-862
4.3
2020-03-17 CVE-2019-20105 Missing Authentication for Critical Function vulnerability in Atlassian Application Links
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.
network
low complexity
atlassian CWE-306
4.9
2020-02-13 CVE-2012-1500 Cross-site Scripting vulnerability in Atlassian Greenhopper and Jira
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.
network
low complexity
atlassian CWE-79
5.4
2020-02-12 CVE-2019-20100 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira
The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF).
network
low complexity
atlassian CWE-352
4.7
2020-02-12 CVE-2019-20099 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF).
network
low complexity
atlassian CWE-352
4.3
2020-02-12 CVE-2019-20098 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF).
network
low complexity
atlassian CWE-352
4.3
2020-02-06 CVE-2019-20405 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
4.3
2020-02-06 CVE-2019-20404 Unspecified vulnerability in Atlassian Jira Data Center and Jira Server
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
network
low complexity
atlassian
4.3