Show filters
445 Total Results
Displaying 61-70 of 445
Sort by:
Attacker Value
Unknown
CVE-2021-43957
Disclosure Date: March 14, 2022 (last updated October 07, 2023)
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.
0
Attacker Value
Unknown
CVE-2021-43955
Disclosure Date: March 14, 2022 (last updated October 07, 2023)
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2021-43958
Disclosure Date: March 14, 2022 (last updated October 07, 2023)
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via a improper restriction of excess authentication attempts vulnerability.
0
Attacker Value
Unknown
CVE-2021-43956
Disclosure Date: March 14, 2022 (last updated October 07, 2023)
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
0
Attacker Value
Unknown
CVE-2021-43954
Disclosure Date: March 07, 2022 (last updated October 07, 2023)
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2021-39114
Disclosure Date: February 09, 2022 (last updated October 07, 2023)
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
0
Attacker Value
Unknown
CVE-2021-43947
Disclosure Date: January 06, 2022 (last updated October 07, 2023)
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.
0
Attacker Value
Unknown
CVE-2021-43952
Disclosure Date: January 06, 2022 (last updated October 07, 2023)
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.
0
Attacker Value
Unknown
CVE-2021-43950
Disclosure Date: January 06, 2022 (last updated October 07, 2023)
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.
0
Attacker Value
Unknown
CVE-2021-43949
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.
0