Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8Atlassian

Critical [CVE-2022-43782] Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application

Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3

CVE-2022-43782
Bamboo / Crowd / Fisheye
Nov 17, 2022
Critical9.8Atlassian

Critical [CVE-2022-43781] Bitbucket: There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

CVE-2022-43781
Bitbucket
Nov 17, 2022
High8.8Atlassian

High [CVE-2022-36803] The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2

The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.

CVE-2022-36803
Jira
Oct 14, 2022
High8.8Atlassian Exploited CISA KEV

High [CVE-2022-36804] Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before…

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

CVE-2022-36804
Bitbucket
Aug 25, 2022
High7.2Atlassian

High [CVE-2022-36799] This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been…

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code in velocity templates. The affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1.

CVE-2022-36799
Jira
Aug 1, 2022
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2022-26138] The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the…

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CVE-2022-26138
Confluence
Jul 20, 2022
Critical9.8Atlassian

Critical [CVE-2022-26136] Confluence: vulnerability in multiple Atlassian products

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Affected products named by the advisory: Confluence; Jira Service Management; Bitbucket; Crowd; and 2 more.

CVE-2022-26136
ConfluenceJiraBitbucketBamboo / Crowd / Fisheye
Jul 20, 2022
High8.8Atlassian

High [CVE-2022-26137] Confluence: vulnerability in multiple Atlassian products

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Affected products named by the advisory: Confluence; Jira Service Management; Bitbucket; Crowd; and 2 more.

CVE-2022-26137
ConfluenceJiraBitbucketBamboo / Crowd / Fisheye
Jul 20, 2022
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2022-26134] In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVE-2022-26134
Confluence
Jun 3, 2022
Critical9.8Atlassian

Critical [CVE-2022-26133] SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later…

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.

CVE-2022-26133
Bitbucket
Apr 20, 2022
Critical9.8Atlassian

Critical [CVE-2022-0540] Jira Service Management: vulnerability in Jira Seraph

A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. Affected product named by the advisory: Jira Service Management.

CVE-2022-0540
Jira
Apr 20, 2022
High8.8Atlassian

High [CVE-2021-39114] Confluence Data Center: Affected versions of Atlassian Confluence Server and Data Center

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

CVE-2021-39114
Confluence
Apr 5, 2022
Critical9.8Atlassian

Critical [CVE-2021-43958] Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login…

Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via a improper restriction of excess authentication attempts vulnerability.

CVE-2021-43958
Bamboo / Crowd / Fisheye
Mar 16, 2022
High7.5Atlassian

High [CVE-2020-29446 +1] Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files

Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.

CVE-2020-29446CVE-2021-43957
Bamboo / Crowd / Fisheye
Mar 16, 2022
High7.2Atlassian

High [CVE-2021-43944] This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been…

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43944
Jira
Mar 8, 2022
High7.8Atlassian

High [CVE-2021-43940] Affected versions of Atlassian Confluence Server and Data Center

Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CVE-2021-43940
Confluence
Feb 15, 2022
High7.2Atlassian

High [CVE-2021-43947] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43947
Jira
Jan 6, 2022
High7.5Atlassian

High [CVE-2021-41311] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.

CVE-2021-41311
Jira
Dec 8, 2021
High7.5Atlassian

High [CVE-2021-41312] Jira Service Management: Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.

CVE-2021-41312
Jira
Nov 3, 2021
High7.5Atlassian

High [CVE-2021-41307] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie Chart Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0.

CVE-2021-41307
Jira
Oct 26, 2021