Show filters
51 Total Results
Displaying 21-30 of 51
Sort by:
Attacker Value
Unknown
CVE-2019-15007
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.
0
Attacker Value
Unknown
CVE-2019-15009
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.
0
Attacker Value
Unknown
CVE-2019-15005
Disclosure Date: November 08, 2019 (last updated November 27, 2024)
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.
0
Attacker Value
Unknown
CVE-2018-20239
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a plugin in various Atlassian products where the following are affected: Confluence before version 6.15.2, Crucible before version 4.7.0, Crowd before version 3.4.3, Fisheye before version 4.7.0, Jira before version 7.13.3 and 8.x before 8.1.0.
0
Attacker Value
Unknown
CVE-2018-20240
Disclosure Date: February 20, 2019 (last updated November 27, 2024)
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.
0
Attacker Value
Unknown
CVE-2018-20241
Disclosure Date: February 20, 2019 (last updated November 27, 2024)
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.
0
Attacker Value
Unknown
CVE-2018-13399
Disclosure Date: October 16, 2018 (last updated November 27, 2024)
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
0
Attacker Value
Unknown
CVE-2018-13398
Disclosure Date: September 18, 2018 (last updated November 27, 2024)
The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2018-13392
Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.
0
Attacker Value
Unknown
CVE-2018-13388
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.
0