Crucible

Atlassian · 52 CVEs

CVE-2024-21683
HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center an…

May 21, 2024

CVE-2022-26137
HIGH

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Fi…

Jul 20, 2022

CVE-2022-26136
CRITICAL

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used…

Jul 20, 2022

CVE-2021-43958
CRITICAL

Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login…

Mar 16, 2022

CVE-2021-43957
HIGH

Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct…

Mar 16, 2022

CVE-2021-43956
MEDIUM

The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbit…

Mar 16, 2022

CVE-2021-43955
MEDIUM

The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote at…

Mar 16, 2022

CVE-2021-43954
MEDIUM

The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have…

Mar 14, 2022

CVE-2020-14192
MEDIUM

Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information D…

Feb 1, 2021

CVE-2020-29446
MEDIUM

Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct O…

Jan 18, 2021

CVE-2020-29447
MEDIUM

Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of…

Dec 21, 2020

CVE-2020-14190
HIGH

Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supp…

Nov 25, 2020

CVE-2020-14191
HIGH

Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a D…

Nov 25, 2020

CVE-2020-4026
MEDIUM

The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before…

Jun 2, 2020

CVE-2020-4023
MEDIUM

The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject a…

Jun 1, 2020

CVE-2020-4018
HIGH

The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setu…

Jun 1, 2020

CVE-2020-4017
MEDIUM

The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible be…

Jun 1, 2020

CVE-2020-4016
MEDIUM

The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before v…

Jun 1, 2020

CVE-2020-4015
MEDIUM

The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attacker…

Jun 1, 2020

CVE-2020-4014
MEDIUM

The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to…

Jun 1, 2020

CVE-2020-4013
MEDIUM

The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary…

Jun 1, 2020

CVE-2019-15009
MEDIUM

The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attac…

Dec 11, 2019

CVE-2019-15008
MEDIUM

The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attacke…

Dec 11, 2019

CVE-2019-15007
MEDIUM

The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary…

Dec 11, 2019

CVE-2019-15005
MEDIUM

The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate…

Nov 8, 2019

Showing 1 to 25 of 52 CVEs