Show filters
501 Total Results
Displaying 361-370 of 501
Sort by:
Attacker Value
Unknown

CVE-2018-13392

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.
0
Attacker Value
Unknown

CVE-2018-13390

Disclosure Date: August 10, 2018 (last updated November 27, 2024)
Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.
0
Attacker Value
Unknown

CVE-2018-13385

Disclosure Date: July 24, 2018 (last updated November 27, 2024)
There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for macOS from 1.0b2 before 2.7.6 are affected by this vulnerability.
0
Attacker Value
Unknown

CVE-2017-18104

Disclosure Date: July 24, 2018 (last updated November 27, 2024)
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.
0
Attacker Value
Unknown

CVE-2018-13386

Disclosure Date: July 24, 2018 (last updated November 27, 2024)
There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for Windows before version 2.6.9 are affected by this vulnerability.
0
Attacker Value
Unknown

CVE-2017-18103

Disclosure Date: July 18, 2018 (last updated November 27, 2024)
The atlassian-http library, as used in various Atlassian products, before version 2.0.2 allows remote attackers to spoof web content in the Mozilla Firefox Browser through uploaded files that have a content-type of application/mathml+xml.
0
Attacker Value
Unknown

CVE-2018-5232

Disclosure Date: July 18, 2018 (last updated November 27, 2024)
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.
0
Attacker Value
Unknown

CVE-2018-5229

Disclosure Date: July 16, 2018 (last updated November 27, 2024)
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of user submitted add-on names.
0
Attacker Value
Unknown

CVE-2018-13387

Disclosure Date: July 16, 2018 (last updated November 27, 2024)
The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7.10.0 before version 7.10.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter as the fix for CVE-2017-18039 was incomplete.
0
Attacker Value
Unknown

CVE-2018-13388

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.
0