Show filters
501 Total Results
Displaying 441-450 of 501
Sort by:
Attacker Value
Unknown

CVE-2017-9508

Disclosure Date: August 24, 2017 (last updated November 26, 2024)
Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.
0
Attacker Value
Unknown

CVE-2017-9509

Disclosure Date: August 24, 2017 (last updated November 26, 2024)
The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.
0
Attacker Value
Unknown

CVE-2017-9512

Disclosure Date: August 24, 2017 (last updated October 17, 2024)
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.
0
Attacker Value
Unknown

CVE-2017-9506

Disclosure Date: August 23, 2017 (last updated November 26, 2024)
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
0
Attacker Value
Unknown

CVE-2017-2284

Disclosure Date: August 02, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-9505

Disclosure Date: June 15, 2017 (last updated November 26, 2024)
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.
Attacker Value
Unknown

CVE-2017-8907

Disclosure Date: June 14, 2017 (last updated October 17, 2024)
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a green build, to create a deployment project and execute arbitrary code on an available Bamboo Agent. By default a local agent is enabled; this means that code execution can occur on the system hosting Bamboo as the user running Bamboo.
0
Attacker Value
Unknown

CVE-2017-2178

Disclosure Date: June 09, 2017 (last updated November 26, 2024)
Untrusted search path vulnerability in Installer of electronic tendering and bid opening system available prior to May 25, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2017-8080

Disclosure Date: May 05, 2017 (last updated November 26, 2024)
Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving image uploads.
0
Attacker Value
Unknown

CVE-2017-8058

Disclosure Date: May 05, 2017 (last updated November 08, 2023)
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.
0