Show filters
144 Total Results
Displaying 41-50 of 144
Sort by:
Attacker Value
Unknown
CVE-2020-4018
Disclosure Date: April 21, 2020 (last updated February 21, 2025)
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2020-4016
Disclosure Date: April 21, 2020 (last updated November 27, 2024)
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2014-2906
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.
0
Attacker Value
Unknown
CVE-2014-2914
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.
0
Attacker Value
Unknown
CVE-2014-3856
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
0
Attacker Value
Unknown
CVE-2019-15008
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.
0
Attacker Value
Unknown
CVE-2019-15007
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.
0
Attacker Value
Unknown
CVE-2019-15009
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.
0
Attacker Value
Unknown
CVE-2019-15005
Disclosure Date: November 08, 2019 (last updated November 27, 2024)
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.
0
Attacker Value
Unknown
CVE-2018-20239
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a plugin in various Atlassian products where the following are affected: Confluence before version 6.15.2, Crucible before version 4.7.0, Crowd before version 3.4.3, Fisheye before version 4.7.0, Jira before version 7.13.3 and 8.x before 8.1.0.
0