Vulnerabilities
Vulnerable Software
Atlassian:  Security Vulnerabilities
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.
CVSS Score
5.9
EPSS Score
0.006
Published
2017-05-05
Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS command execution with a URL substring of sourcetree://cloneRepo/ext:: or sourcetree://checkoutRef/ext:: followed by the command. The Atlassian ID number is SRCTREE-4632.
CVSS Score
9.8
EPSS Score
0.083
Published
2017-05-04
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.
CVSS Score
7.5
EPSS Score
0.044
Published
2017-04-27
Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file.
CVSS Score
9.1
EPSS Score
0.026
Published
2017-04-14
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
CVSS Score
9.8
EPSS Score
0.164
Published
2017-04-10
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
CVSS Score
5.4
EPSS Score
0.007
Published
2017-04-10
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
CVSS Score
4.8
EPSS Score
0.008
Published
2017-04-10
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
CVSS Score
8.8
EPSS Score
0.007
Published
2017-04-10
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.
CVSS Score
4.3
EPSS Score
0.018
Published
2017-04-10
Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
CVSS Score
6.1
EPSS Score
0.021
Published
2017-01-31


Contact Us

Shodan ® - All rights reserved