Atlassian

Confluence

35 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.32%
  • Veröffentlicht 22.09.2026 18:03:03
  • Zuletzt bearbeitet 29.09.2026 13:56:16

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept an unconstrained file_path and open the referenced server-local fil...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 22.09.2026 17:55:37
  • Zuletzt bearbeitet 29.09.2026 14:21:29

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence search uses an ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 22.09.2026 17:47:58
  • Zuletzt bearbeitet 29.09.2026 19:00:07

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connec...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 22.09.2026 17:46:30
  • Zuletzt bearbeitet 28.09.2026 13:35:22

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths. The server o...

  • EPSS 0.33%
  • Veröffentlicht 14.09.2026 19:49:03
  • Zuletzt bearbeitet 30.09.2026 17:51:56

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassia...

Medienbericht
  • EPSS 2.26%
  • Veröffentlicht 10.03.2026 18:53:41
  • Zuletzt bearbeitet 02.04.2026 13:52:39

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any directory b...

  • EPSS 1.52%
  • Veröffentlicht 01.07.2020 02:15:12
  • Zuletzt bearbeitet 21.11.2024 05:32:10

Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected vers...

  • EPSS 0.48%
  • Veröffentlicht 06.02.2020 03:15:10
  • Zuletzt bearbeitet 21.11.2024 04:38:24

The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path envi...

  • EPSS 1.91%
  • Veröffentlicht 19.12.2019 01:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:51

There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Pr...

  • EPSS 1.33%
  • Veröffentlicht 08.11.2019 04:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:51

The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message m...