|
219391
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira_server jira_data_center
|
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnera…
|
CWE-352
Origin Validation Error
|
CVE-2019-20405
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219392
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira_server jira_data_center
|
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulner…
|
NVD-CWE-noinfo
|
CVE-2019-20404
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219393
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira_server jira_data_center
|
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an information disclosure vulnerability.
|
NVD-CWE-noinfo
|
CVE-2019-20403
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219394
|
4.9 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center
|
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an imprope…
|
NVD-CWE-noinfo
|
CVE-2019-20402
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219395
|
6.5 |
MEDIUM
Network
|
atlassian
|
jira_server
|
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF…
|
CWE-352
Origin Validation Error
|
CVE-2019-20401
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219396
|
7.8 |
HIGH
Local
|
atlassian
|
jira_server
|
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hij…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-20400
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219397
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticke…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-20106
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219398
|
7.5 |
HIGH
Network
|
atlassian
|
crowd
|
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vu…
|
CWE-776
XML Entity Expansion
|
CVE-2019-20104
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219399
|
9.8 |
CRITICAL
Network
|
jobberbase
|
jobberbase
|
Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.
|
CWE-89
SQL Injection
|
CVE-2019-20447
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219400
|
6.1 |
MEDIUM
Network
|
auth0
|
login_by_auth0
|
The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20173
|
2024-11-21 13:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|