Show filters
501 Total Results
Displaying 321-330 of 501
Sort by:
Attacker Value
Unknown
CVE-2019-3395
Disclosure Date: March 25, 2019 (last updated November 27, 2024)
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.
0
Attacker Value
Unknown
CVE-2018-20236
Disclosure Date: March 08, 2019 (last updated November 27, 2024)
There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system.
0
Attacker Value
Unknown
CVE-2018-20235
Disclosure Date: March 08, 2019 (last updated November 27, 2024)
There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
0
Attacker Value
Unknown
CVE-2018-20234
Disclosure Date: March 08, 2019 (last updated November 27, 2024)
There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.
0
Attacker Value
Unknown
CVE-2018-20240
Disclosure Date: February 20, 2019 (last updated November 27, 2024)
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.
0
Attacker Value
Unknown
CVE-2018-20241
Disclosure Date: February 20, 2019 (last updated November 27, 2024)
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.
0
Attacker Value
Unknown
CVE-2018-20238
Disclosure Date: February 13, 2019 (last updated November 27, 2024)
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
0
Attacker Value
Unknown
CVE-2018-20232
Disclosure Date: February 13, 2019 (last updated November 27, 2024)
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting.
0
Attacker Value
Unknown
CVE-2018-13404
Disclosure Date: February 13, 2019 (last updated November 27, 2024)
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in some cases obtain service information from internal network resources via a Server Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2018-13403
Disclosure Date: February 13, 2019 (last updated November 27, 2024)
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.
0