target entity

Atlassian

13 source-linked records in the current knowledge graph.

high

CVE-2021-26086: Atlassian Jira Server and Data Center Path Traversal Vulnerability

Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-26086EPSS 100.0%AtlassianJira Server and Data Center
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-22518: Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-22518EPSS 100.0%AtlassianConfluence Data Center and Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-22515: Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.

CVE-2023-22515EPSS 99.2%AtlassianConfluence Data Center and Server
CISA KEV ↗ · unattributed attribution
high

CVE-2022-36804: Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request. Required action: Apply updates per vendor instructions.

CVE-2022-36804EPSS 99.1%AtlassianBitbucket Server and Data Center
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26138: Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group. Required action: Apply updates per vendor instructions.

CVE-2022-26138EPSS 98.2%AtlassianConfluence
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26134: Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.

CVE-2022-26134EPSS 100.0%AtlassianConfluence Server/Data Center
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-3398: Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution. Required action: Apply updates per vendor instructions.

CVE-2019-3398EPSS 97.2%AtlassianConfluence Server and Data Center
CISA KEV ↗ · unattributed attribution