Crucible
Atlassian · 52 CVEs
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center an…
May 21, 2024
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Fi…
Jul 20, 2022
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used…
Jul 20, 2022
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login…
Mar 16, 2022
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct…
Mar 16, 2022
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbit…
Mar 16, 2022
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote at…
Mar 16, 2022
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have…
Mar 14, 2022
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information D…
Feb 1, 2021
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct O…
Jan 18, 2021
Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of…
Dec 21, 2020
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supp…
Nov 25, 2020
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a D…
Nov 25, 2020
The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before…
Jun 2, 2020
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject a…
Jun 1, 2020
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setu…
Jun 1, 2020
The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible be…
Jun 1, 2020
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before v…
Jun 1, 2020
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attacker…
Jun 1, 2020
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to…
Jun 1, 2020
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary…
Jun 1, 2020
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attac…
Dec 11, 2019
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attacke…
Dec 11, 2019
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary…
Dec 11, 2019
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate…
Nov 8, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-21683 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Executio… | HIGH | 88.27% | May 21, 2024 |
| CVE-2022-26137 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application… | HIGH | 2.34% | Jul 20, 2022 |
| CVE-2022-26136 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impa… | CRITICAL | 5.35% | Jul 20, 2022 |
| CVE-2021-43958 | Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not ch… | CRITICAL | 1.47% | Mar 16, 2022 |
| CVE-2021-43957 | Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability… | HIGH | 1.29% | Mar 16, 2022 |
| CVE-2021-43956 | The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a protot… | MEDIUM | 0.73% | Mar 16, 2022 |
| CVE-2021-43955 | The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about inst… | MEDIUM | 0.88% | Mar 16, 2022 |
| CVE-2021-43954 | The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enu… | MEDIUM | 0.77% | Mar 14, 2022 |
| CVE-2020-14192 | Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen re… | MEDIUM | 0.87% | Feb 1, 2021 |
| CVE-2020-29446 | Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in… | MEDIUM | 1.18% | Jan 18, 2021 |
| CVE-2020-29447 | Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file… | MEDIUM | 1.00% | Dec 21, 2020 |
| CVE-2020-14190 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versio… | HIGH | 1.23% | Nov 25, 2020 |
| CVE-2020-14191 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in… | HIGH | 1.23% | Nov 25, 2020 |
| CVE-2020-4026 | The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before… | MEDIUM | 0.75% | Jun 2, 2020 |
| CVE-2020-4023 | The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross… | MEDIUM | 0.77% | Jun 1, 2020 |
| CVE-2020-4018 | The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forge… | HIGH | 0.57% | Jun 1, 2020 |
| CVE-2020-4017 | The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attacke… | MEDIUM | 1.24% | Jun 1, 2020 |
| CVE-2020-4016 | The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to… | MEDIUM | 1.24% | Jun 1, 2020 |
| CVE-2020-4015 | The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via… | MEDIUM | 0.96% | Jun 1, 2020 |
| CVE-2020-4014 | The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings… | MEDIUM | 0.77% | Jun 1, 2020 |
| CVE-2020-4013 | The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scri… | MEDIUM | 0.63% | Jun 1, 2020 |
| CVE-2019-15009 | The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite… | MEDIUM | 0.73% | Dec 11, 2019 |
| CVE-2019-15008 | The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScrip… | MEDIUM | 0.74% | Dec 11, 2019 |
| CVE-2019-15007 | The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scri… | MEDIUM | 0.60% | Dec 11, 2019 |
| CVE-2019-15005 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results… | MEDIUM | 1.33% | Nov 8, 2019 |
Showing 1 to 25 of 52 CVEs