CVE-2018-13388
- EPSS 0.17%
- Veröffentlicht 10.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:47:00
The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.
CVE-2017-16859
- EPSS 1.36%
- Veröffentlicht 28.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:06
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a p...
CVE-2018-5228
- EPSS 0.26%
- Veröffentlicht 24.04.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:22
The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.
CVE-2018-5223
- EPSS 0.91%
- Veröffentlicht 29.03.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:22
Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repository in Fisheye or Crucible can e...
CVE-2017-18094
- EPSS 0.15%
- Veröffentlicht 22.03.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:20
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerabili...
CVE-2017-18095
- EPSS 0.21%
- Veröffentlicht 19.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:21
The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.
CVE-2017-18093
- EPSS 0.18%
- Veröffentlicht 19.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:20
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site s...
CVE-2017-18092
- EPSS 0.18%
- Veröffentlicht 19.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:20
The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of...
CVE-2017-18091
- EPSS 0.18%
- Veröffentlicht 16.02.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:20
The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scrip...
CVE-2017-18089
- EPSS 0.18%
- Veröffentlicht 16.02.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:20
The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited revi...