|
250851
|
8.8 |
HIGH
Network
|
atlassian
|
bamboo
|
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2017-18042
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250852
|
5.4 |
MEDIUM
Network
|
atlassian
|
bamboo
|
The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabili…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18041
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250853
|
5.4 |
MEDIUM
Network
|
atlassian
|
bamboo
|
The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18040
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250854
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira
|
The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabilit…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18039
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250855
|
5.3 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the de…
|
CWE-22
Path Traversal
|
CVE-2017-18038
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250856
|
4.3 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports via a Server Side Req…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-18036
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250857
|
4.3 |
MEDIUM
Network
|
atlassian
|
fisheye crucible
|
The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attacker…
|
CWE-862
Missing Authorization
|
CVE-2017-18035
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250858
|
5.4 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or …
|
CWE-79
Cross-site Scripting
|
CVE-2017-18034
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250859
|
6.5 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), fro…
|
CWE-22
Path Traversal
|
CVE-2017-18037
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250860
|
7.8 |
HIGH
Local
|
lcdf
|
gifsicle
|
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, becau…
|
CWE-415
Double Free
|
CVE-2017-18120
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|