Show filters
501 Total Results
Displaying 291-300 of 501
Sort by:
Attacker Value
Unknown
CVE-2019-8445
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
0
Attacker Value
Unknown
CVE-2019-14999
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.
0
Attacker Value
Unknown
CVE-2019-11585
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
0
Attacker Value
Unknown
CVE-2019-11588
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2019-8446
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
0
Attacker Value
Unknown
CVE-2019-15053
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
0
Attacker Value
Unknown
CVE-2019-8448
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2019-11581 — Atlassian JIRA Template injection vulnerability RCE
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2018-20826
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.
0
Attacker Value
Unknown
CVE-2018-20827
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter.
0