|
219711
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira_server jira_data_center
|
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an information disclosure vulnerability.
|
NVD-CWE-noinfo
|
CVE-2019-20403
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219712
|
4.9 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center
|
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an imprope…
|
NVD-CWE-noinfo
|
CVE-2019-20402
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219713
|
6.5 |
MEDIUM
Network
|
atlassian
|
jira_server
|
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF…
|
CWE-352
Origin Validation Error
|
CVE-2019-20401
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219714
|
7.8 |
HIGH
Local
|
atlassian
|
jira_server
|
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hij…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-20400
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219715
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticke…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-20106
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219716
|
7.5 |
HIGH
Network
|
atlassian
|
crowd
|
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vu…
|
CWE-776
XML Entity Expansion
|
CVE-2019-20104
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219717
|
9.8 |
CRITICAL
Network
|
jobberbase
|
jobberbase
|
Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.
|
CWE-89
SQL Injection
|
CVE-2019-20447
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219718
|
6.1 |
MEDIUM
Network
|
auth0
|
login_by_auth0
|
The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20173
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219719
|
6.1 |
MEDIUM
Network
|
auth0
|
lock
|
Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20174
|
2024-11-21 13:38 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219720
|
6.5 |
MEDIUM
Network
|
gnome opensuse fedoraproject debian canonical netapp
|
librsvg leap fedora debian_linux ubuntu_linux active_iq_unified_manager
|
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so th…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-20446
|
2024-11-21 13:38 |
2020-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|