Show filters
501 Total Results
Displaying 161-170 of 501
Sort by:
Attacker Value
Unknown

CVE-2020-36238

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions check.
Attacker Value
Unknown

CVE-2021-26072

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
Attacker Value
Unknown

CVE-2020-36286

Disclosure Date: April 01, 2021 (last updated November 28, 2024)
The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field.
Attacker Value
Unknown

CVE-2021-26071

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.
Attacker Value
Unknown

CVE-2020-36240

Disclosure Date: February 28, 2021 (last updated November 28, 2024)
The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Attacker Value
Unknown

CVE-2020-12873

Disclosure Date: February 19, 2021 (last updated February 22, 2025)
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.
Attacker Value
Unknown

CVE-2021-26068

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.
Attacker Value
Unknown

CVE-2020-36233

Disclosure Date: February 16, 2021 (last updated February 22, 2025)
The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
Attacker Value
Unknown

CVE-2020-36235

Disclosure Date: February 04, 2021 (last updated November 28, 2024)
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
Attacker Value
Unknown

CVE-2020-36237

Disclosure Date: February 04, 2021 (last updated November 28, 2024)
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.