CVE-2017-18097
- EPSS 0.65%
- Veröffentlicht 06.04.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:21
The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability...
CVE-2017-18098
- EPSS 0.87%
- Veröffentlicht 06.04.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:21
The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields.
CVE-2017-18039
- EPSS 1.11%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:13
The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter.
CVE-2017-16863
- EPSS 0.81%
- Veröffentlicht 18.01.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:07
The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.
CVE-2017-18033
- EPSS 0.55%
- Veröffentlicht 18.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:12
The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.
CVE-2017-16865
- EPSS 0.69%
- Veröffentlicht 17.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:07
The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to a...
CVE-2017-14594
- EPSS 1.04%
- Veröffentlicht 12.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:13:10
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query...
CVE-2017-16862
- EPSS 0.64%
- Veröffentlicht 12.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:07
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.
CVE-2017-16864
- EPSS 1.17%
- Veröffentlicht 12.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:07
The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.
CVE-2017-5983
- EPSS 16.37%
- Veröffentlicht 10.04.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serializ...