Vulnerabilities > Atlassian > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-01-28 CVE-2021-26067 Information Exposure vulnerability in Atlassian Bamboo
Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint.
network
low complexity
atlassian CWE-200
5.3
2021-01-19 CVE-2020-29450 Unrestricted Upload of File with Dangerous Type vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature.
network
low complexity
atlassian CWE-434
6.5
2021-01-18 CVE-2020-29446 Authorization Bypass Through User-Controlled Key vulnerability in Atlassian Crucible
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory.
network
low complexity
atlassian CWE-639
5.3
2020-12-21 CVE-2020-29447 Unrestricted Upload of File with Dangerous Type vulnerability in Atlassian Crucible
Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews.
network
low complexity
atlassian CWE-434
4.3
2020-11-30 CVE-2020-14193 Injection vulnerability in Atlassian Automation for Jira
Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories via a template injection vulnerability in Jira smart values using mustache partials.
network
low complexity
atlassian CWE-74
5.4
2020-10-15 CVE-2020-14185 Missing Authorization vulnerability in Atlassian Jira
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource.
network
low complexity
atlassian CWE-862
5.3
2020-10-12 CVE-2020-14184 Cross-site Scripting vulnerability in Atlassian Jira
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files.
network
low complexity
atlassian CWE-79
5.4
2020-10-06 CVE-2020-14183 Information Exposure vulnerability in Atlassian Jira
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers.
network
low complexity
atlassian CWE-200
4.3
2020-10-01 CVE-2019-20903 Cross-site Scripting vulnerability in Atlassian Editor-Core
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
network
low complexity
atlassian CWE-79
5.4
2020-09-21 CVE-2020-14180 Unspecified vulnerability in Atlassian Jira Service Desk
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource.
network
low complexity
atlassian
4.3