Show filters
501 Total Results
Displaying 321-330 of 501
Sort by:
Attacker Value
Unknown

CVE-2019-3395

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.
0
Attacker Value
Unknown

CVE-2018-20236

Disclosure Date: March 08, 2019 (last updated November 27, 2024)
There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system.
0
Attacker Value
Unknown

CVE-2018-20235

Disclosure Date: March 08, 2019 (last updated November 27, 2024)
There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
0
Attacker Value
Unknown

CVE-2018-20234

Disclosure Date: March 08, 2019 (last updated November 27, 2024)
There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.
0
Attacker Value
Unknown

CVE-2018-20240

Disclosure Date: February 20, 2019 (last updated November 27, 2024)
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.
0
Attacker Value
Unknown

CVE-2018-20241

Disclosure Date: February 20, 2019 (last updated November 27, 2024)
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.
0
Attacker Value
Unknown

CVE-2018-20238

Disclosure Date: February 13, 2019 (last updated November 27, 2024)
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
0
Attacker Value
Unknown

CVE-2018-20232

Disclosure Date: February 13, 2019 (last updated November 27, 2024)
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting.
0
Attacker Value
Unknown

CVE-2018-13404

Disclosure Date: February 13, 2019 (last updated November 27, 2024)
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in some cases obtain service information from internal network resources via a Server Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown

CVE-2018-13403

Disclosure Date: February 13, 2019 (last updated November 27, 2024)
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.
0