|
249721
|
6.1 |
MEDIUM
Network
|
atlassian
|
bamboo
|
The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18081
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249722
|
8.8 |
HIGH
Network
|
atlassian
|
bamboo
|
The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2017-18080
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249723
|
8.8 |
HIGH
Network
|
atlassian
|
bamboo
|
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2017-18042
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249724
|
5.4 |
MEDIUM
Network
|
atlassian
|
bamboo
|
The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabili…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18041
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249725
|
5.4 |
MEDIUM
Network
|
atlassian
|
bamboo
|
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18040
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249726
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira
|
The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabilit…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18039
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249727
|
5.3 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the de…
|
CWE-22
Path Traversal
|
CVE-2017-18038
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249728
|
4.3 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports via a Server Side Req…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-18036
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249729
|
4.3 |
MEDIUM
Network
|
atlassian
|
fisheye crucible
|
The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attacker…
|
CWE-862
Missing Authorization
|
CVE-2017-18035
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249730
|
5.4 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or …
|
CWE-79
Cross-site Scripting
|
CVE-2017-18034
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|