Show filters
501 Total Results
Displaying 241-250 of 501
Sort by:
Attacker Value
Unknown
CVE-2019-20899
Disclosure Date: March 23, 2020 (last updated November 28, 2024)
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.
0
Attacker Value
Unknown
CVE-2020-9344
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.
0
Attacker Value
Unknown
CVE-2019-20105
Disclosure Date: March 17, 2020 (last updated February 21, 2025)
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.
0
Attacker Value
Unknown
CVE-2019-20407
Disclosure Date: March 17, 2020 (last updated February 21, 2025)
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.
0
Attacker Value
Unknown
CVE-2012-1500
Disclosure Date: February 13, 2020 (last updated February 21, 2025)
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.
0
Attacker Value
Unknown
CVE-2019-20106
Disclosure Date: February 05, 2020 (last updated February 21, 2025)
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
0
Attacker Value
Unknown
CVE-2019-20104
Disclosure Date: February 05, 2020 (last updated February 21, 2025)
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
0
Attacker Value
Unknown
CVE-2019-20406
Disclosure Date: February 05, 2020 (last updated February 21, 2025)
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.
0
Attacker Value
Unknown
CVE-2019-20404
Disclosure Date: February 04, 2020 (last updated November 27, 2024)
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
0
Attacker Value
Unknown
CVE-2019-20403
Disclosure Date: February 04, 2020 (last updated November 27, 2024)
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an information disclosure vulnerability.
0