Vulnerabilities > Atlassian > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-08-23 CVE-2017-9506 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Oauth
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
network
low complexity
atlassian CWE-918
6.1
2017-06-15 CVE-2017-9505 Incorrect Default Permissions vulnerability in Atlassian Confluence
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments.
network
low complexity
atlassian CWE-276
4.3
2017-05-05 CVE-2017-8058 Improper Certificate Validation vulnerability in Atlassian Hipchat 3.16.1
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.
network
high complexity
atlassian CWE-295
5.9
2017-04-10 CVE-2016-4320 Path Traversal vulnerability in Atlassian Bitbucket
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.
network
low complexity
atlassian CWE-22
4.3
2017-04-10 CVE-2016-4318 Cross-site Scripting vulnerability in Atlassian Jira
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
network
low complexity
atlassian CWE-79
4.8
2017-04-10 CVE-2016-4317 Cross-site Scripting vulnerability in Atlassian Confluence
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
network
low complexity
atlassian CWE-79
5.4
2017-01-31 CVE-2016-6285 Cross-site Scripting vulnerability in Atlassian Jira
Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
network
low complexity
atlassian CWE-79
6.1
2017-01-18 CVE-2016-6283 Cross-site Scripting vulnerability in Atlassian Confluence
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
network
low complexity
atlassian CWE-79
6.1
2016-04-11 CVE-2015-8399 Information Exposure vulnerability in Atlassian Confluence
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.
network
low complexity
atlassian CWE-200
4.3
2016-04-11 CVE-2015-8398 Cross-site Scripting vulnerability in Atlassian Confluence
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
network
low complexity
atlassian CWE-79
6.1