CVE-2026-77260
- EPSS 0.32%
- Veröffentlicht 22.09.2026 18:03:03
- Zuletzt bearbeitet 29.09.2026 13:56:16
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept an unconstrained file_path and open the referenced server-local fil...
CVE-2026-77251
- EPSS 0.25%
- Veröffentlicht 22.09.2026 17:55:37
- Zuletzt bearbeitet 29.09.2026 14:21:29
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence search uses an ...
CVE-2026-77265
- EPSS 0.26%
- Veröffentlicht 22.09.2026 17:47:58
- Zuletzt bearbeitet 29.09.2026 19:00:07
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connec...
CVE-2026-77270
- EPSS 0.4%
- Veröffentlicht 22.09.2026 17:46:30
- Zuletzt bearbeitet 28.09.2026 13:35:22
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths. The server o...
CVE-2026-73496
- EPSS 0.33%
- Veröffentlicht 14.09.2026 19:49:03
- Zuletzt bearbeitet 30.09.2026 17:51:56
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassia...
- EPSS 2.26%
- Veröffentlicht 10.03.2026 18:53:41
- Zuletzt bearbeitet 02.04.2026 13:52:39
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any directory b...
CVE-2021-43945
- EPSS 0.58%
- Veröffentlicht 28.02.2022 01:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:03
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConf...
CVE-2021-43953
- EPSS 0.48%
- Veröffentlicht 15.02.2022 03:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:04
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentati...
- EPSS 4.12%
- Veröffentlicht 06.01.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:03
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of h...
CVE-2021-41312
- EPSS 1.17%
- Veröffentlicht 03.11.2021 04:15:09
- Zuletzt bearbeitet 21.11.2024 06:26:01
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication...