CVE-2019-3401
- EPSS 12.72%
- Veröffentlicht 22.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:02
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
CVE-2019-3402
- EPSS 8.95%
- Veröffentlicht 22.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:02
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName ...
CVE-2019-3403
- EPSS 52.64%
- Veröffentlicht 22.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:02
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
CVE-2018-20824
- EPSS 37.99%
- Veröffentlicht 03.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:15
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
CVE-2019-3399
- EPSS 2.05%
- Veröffentlicht 30.04.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:01
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.
CVE-2018-13403
- EPSS 0.94%
- Veröffentlicht 13.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:47:02
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross s...
CVE-2018-13404
- EPSS 1.14%
- Veröffentlicht 13.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:47:02
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from...
CVE-2018-20232
- EPSS 0.91%
- Veröffentlicht 13.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:08
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved ...
CVE-2018-13401
- EPSS 1.36%
- Veröffentlicht 23.10.2018 13:29:03
- Zuletzt bearbeitet 21.11.2024 03:47:01
The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7....
CVE-2018-13402
- EPSS 1.36%
- Veröffentlicht 23.10.2018 13:29:03
- Zuletzt bearbeitet 21.11.2024 03:47:02
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before ve...