Atlassian Bamboo / Crowd / Fisheye Vulnerabilities & Security Advisories
20 advisories tracked · Atlassian (security@atlassian.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Atlassian advisory that VulniPulse classified as Bamboo / Crowd / Fisheye, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 4 critical, 9 high, 7 medium.
Android app · Google Play
Monitor Atlassian CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Atlassian (security@atlassian.com CNA) via NVD
Atlassian is its own CVE Numbering Authority. VulniPulse ingests Atlassian's CVEs from the NVD CNA feed (security@atlassian.com), each linking to its security advisory / Jira ticket. Covers Confluence (Server & Data Center), Jira (Software & Service Management), Bitbucket, Bamboo, Crowd and Fisheye/Crucible — self-hosted Confluence/Jira are repeatedly hit by mass-exploited RCE and auth-bypass bugs (CVE-2023-22515, CVE-2022-26134), so a huge patch-now audience.
Latest Atlassian Bamboo / Crowd / Fisheye advisories
Medium [CVE-2021-43956] The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML…
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
Medium [CVE-2021-43955] The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers…
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.
Medium [CVE-2021-43954] The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add…
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
Medium [CVE-2020-36240] The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated…
The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
Medium [CVE-2020-14192] Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.
Medium [CVE-2021-26067] Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace
Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint. The affected versions are before version 7.2.2.
Medium [CVE-2020-29446] Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.