Show filters
501 Total Results
Displaying 241-250 of 501
Sort by:
Attacker Value
Unknown

CVE-2019-20899

Disclosure Date: March 23, 2020 (last updated November 28, 2024)
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
Attacker Value
Unknown

CVE-2020-9344

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.
Attacker Value
Unknown

CVE-2019-20105

Disclosure Date: March 17, 2020 (last updated February 21, 2025)
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.
Attacker Value
Unknown

CVE-2019-20407

Disclosure Date: March 17, 2020 (last updated February 21, 2025)
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.
Attacker Value
Unknown

CVE-2012-1500

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.
Attacker Value
Unknown

CVE-2019-20106

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
Attacker Value
Unknown

CVE-2019-20104

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
Attacker Value
Unknown

CVE-2019-20406

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.
Attacker Value
Unknown

CVE-2019-20404

Disclosure Date: February 04, 2020 (last updated November 27, 2024)
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
Attacker Value
Unknown

CVE-2019-20403

Disclosure Date: February 04, 2020 (last updated November 27, 2024)
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an information disclosure vulnerability.