Atlassian

Fisheye

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 10.07.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:47:00

The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.

  • EPSS 1.36%
  • Veröffentlicht 28.06.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:17:06

The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a p...

  • EPSS 0.26%
  • Veröffentlicht 24.04.2018 12:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:22

The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.

  • EPSS 0.91%
  • Veröffentlicht 29.03.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:22

Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repository in Fisheye or Crucible can e...

  • EPSS 0.15%
  • Veröffentlicht 22.03.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:20

Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabili...

  • EPSS 0.18%
  • Veröffentlicht 19.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:20

Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site s...

  • EPSS 0.18%
  • Veröffentlicht 16.02.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:20

The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scrip...

  • EPSS 0.23%
  • Veröffentlicht 16.02.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:20

Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit au...

  • EPSS 0.11%
  • Veröffentlicht 02.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:13

The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository...

  • EPSS 0.14%
  • Veröffentlicht 02.02.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:13

The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnera...