Refine your search

405 vulnerabilities found for by Atlassian

CVE-2026-21584 (GCVE-0-2026-21584)
Vulnerability from cvelistv5
Published
2026-08-18 22:00
Modified
2026-08-28 15:04
CWE
  • Improper Authorization
Summary
This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.22 * Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.10 See the release notes (https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html). You can download the latest version of Bamboo Data Center from the download center (https://www.atlassian.com/software/bamboo/download-archives). This vulnerability was reported via our Penetration Testing program.
Impacted products
Vendor Product Version
Atlassian Bamboo Data Center Version: 12.1.0 to 12.1.9
Version: 12.0.0 to 12.0.2
Version: 11.0.0 to 11.0.8
Version: 10.2.0 to 10.2.21
Version: 10.1.0 to 10.1.1
Version: 10.0.0 to 10.0.3
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-21584",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-20T03:56:06.324621Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-28T15:04:12.086Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Bamboo Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "12.1.0 to 12.1.9"
            },
            {
              "status": "affected",
              "version": "12.0.0 to 12.0.2"
            },
            {
              "status": "affected",
              "version": "11.0.0 to 11.0.8"
            },
            {
              "status": "affected",
              "version": "10.2.0 to 10.2.21"
            },
            {
              "status": "affected",
              "version": "10.1.0 to 10.1.1"
            },
            {
              "status": "affected",
              "version": "10.0.0 to 10.0.3"
            },
            {
              "status": "unaffected",
              "version": "12.1.10"
            },
            {
              "status": "unaffected",
              "version": "10.2.22"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. \n\t\n\tThis Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. \n\t\n\tAtlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\t\t\n\t\t* Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.22\n\t\t\n\t\t* Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.10\n\t\t\n\t\t\n\t\n\tSee the release notes (https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html). You can download the latest version of Bamboo Data Center from the download center (https://www.atlassian.com/software/bamboo/download-archives). \n\t\n\tThis vulnerability was reported via our Penetration Testing program."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 7.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-18T22:00:00.499Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999768"
        },
        {
          "url": "https://jira.atlassian.com/browse/BAM-26468"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2026-21584",
    "datePublished": "2026-08-18T22:00:00.499Z",
    "dateReserved": "2026-01-01T00:00:40.721Z",
    "dateUpdated": "2026-08-28T15:04:12.086Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-21582 (GCVE-0-2026-21582)
Vulnerability from cvelistv5
Published
2026-08-18 22:00
Modified
2026-08-20 18:34
CWE
  • BASM (Broken Authentication & Session Management)
Summary
This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user. Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2 See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive). This vulnerability was reported via our Penetration Testing program.
Impacted products
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-21582",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-20T03:56:07.440214Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-287",
                "description": "CWE-287 Improper Authentication",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-20T18:34:02.178Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Crowd Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "7.2.1"
            },
            {
              "status": "unaffected",
              "version": "7.2.2 to 7.2.3"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Internal"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity BASM (Broken Authentication \u0026 Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center.\r\n\r\nThis BASM (Broken Authentication \u0026 Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user.\r\n\t\r\n\tAtlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n\t\t\r\n\t\tCrowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2\r\n\t\t\r\n\t\t\r\n\t\r\n\tSee the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive). \r\n\t\r\n\tThis vulnerability was reported via our Penetration Testing program."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "BASM (Broken Authentication \u0026 Session Management)",
              "lang": "en",
              "type": "BASM (Broken Authentication \u0026 Session Management)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-18T22:00:00.412Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999768"
        },
        {
          "url": "https://jira.atlassian.com/browse/CWD-6562"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2026-21582",
    "datePublished": "2026-08-18T22:00:00.412Z",
    "dateReserved": "2026-01-01T00:00:40.721Z",
    "dateUpdated": "2026-08-20T18:34:02.178Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-21580 (GCVE-0-2026-21580)
Vulnerability from cvelistv5
Published
2026-08-18 22:00
Modified
2026-08-21 14:45
CWE
  • Stored XSS
Summary
This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center and Server from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Bug Bounty program.
Impacted products
Vendor Product Version
Atlassian Confluence Data Center Version: 10.2.0 to 10.2.11
Version: 10.1.0 to 10.1.2
Version: 10.0.2 to 10.0.3
Version: 9.5.1 to 9.5.4
Version: 9.4.0 to 9.4.1
Version: 9.3.1 to 9.3.2
Version: 9.2.0 to 9.2.20
Version: 9.1.0 to 9.1.1
Version: 9.0.3
Version: 8.9.6 to 8.9.8
Version: 8.5.15 to 8.5.31
Version: 7.19.27 to 7.19.30
Create a notification for this product.
   Atlassian Confluence Server Version: 8.5.15 to 8.5.31
Version: 7.19.27 to 7.19.30
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-21580",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-21T03:55:22.938181Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-79",
                "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-21T14:45:07.562Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Confluence Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.0 to 10.2.11"
            },
            {
              "status": "affected",
              "version": "10.1.0 to 10.1.2"
            },
            {
              "status": "affected",
              "version": "10.0.2 to 10.0.3"
            },
            {
              "status": "affected",
              "version": "9.5.1 to 9.5.4"
            },
            {
              "status": "affected",
              "version": "9.4.0 to 9.4.1"
            },
            {
              "status": "affected",
              "version": "9.3.1 to 9.3.2"
            },
            {
              "status": "affected",
              "version": "9.2.0 to 9.2.20"
            },
            {
              "status": "affected",
              "version": "9.1.0 to 9.1.1"
            },
            {
              "status": "affected",
              "version": "9.0.3"
            },
            {
              "status": "affected",
              "version": "8.9.6 to 8.9.8"
            },
            {
              "status": "affected",
              "version": "8.5.15 to 8.5.31"
            },
            {
              "status": "affected",
              "version": "7.19.27 to 7.19.30"
            },
            {
              "status": "unaffected",
              "version": "10.2.13 to 10.2.15"
            },
            {
              "status": "unaffected",
              "version": "9.2.21 to 9.2.23"
            }
          ]
        },
        {
          "product": "Confluence Server",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "8.5.15 to 8.5.31"
            },
            {
              "status": "affected",
              "version": "7.19.27 to 7.19.30"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.4.1",
                  "versionStartIncluding": "9.4.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.3.2",
                  "versionStartIncluding": "9.3.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.2.20",
                  "versionStartIncluding": "9.2.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.1.1",
                  "versionStartIncluding": "9.1.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.0.3:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.9.8",
                  "versionStartIncluding": "8.9.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.5.31",
                  "versionStartIncluding": "8.5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.25:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.26:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.27:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.28:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.29:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.30:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.31:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "7.19.30",
                  "versionStartIncluding": "7.19.27",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.23:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.5.31",
                  "versionStartIncluding": "8.5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.22:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.23:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.24:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.25:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.26:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.27:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.28:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.29:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.30:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.31:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "7.19.30",
                  "versionStartIncluding": "7.19.27",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server.\r\n\r\nThis Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked.\r\n\r\nAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21\r\n\r\n Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center and Server from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Bug Bounty program."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Stored XSS",
              "lang": "en",
              "type": "Stored XSS"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-18T22:00:00.396Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999768"
        },
        {
          "url": "https://jira.atlassian.com/browse/CONFSERVER-104381"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2026-21580",
    "datePublished": "2026-08-18T22:00:00.396Z",
    "dateReserved": "2026-01-01T00:00:40.721Z",
    "dateUpdated": "2026-08-21T14:45:07.562Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-21575 (GCVE-0-2026-21575)
Vulnerability from cvelistv5
Published
2026-07-21 17:00
Modified
2026-07-24 03:55
CWE
  • RCE (Remote Code Execution)
Summary
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13 See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). This vulnerability was reported via our Bug Bounty program.
Impacted products
Vendor Product Version
Atlassian Sourcetree for Mac Version: All versions from 3.4.11 to 3.4.12 inclusive
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-21575",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-23T00:00:00+00:00",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-94",
                "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-24T03:55:49.714Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Sourcetree for Mac",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "All versions from 3.4.11 to 3.4.12 inclusive"
            },
            {
              "status": "unaffected",
              "version": "All versions from 3.4.13"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:atlassian:sourcetree:*:*:*:*:*:macos:*:*",
                  "versionEndExcluding": "3.4.13",
                  "versionStartIncluding": "3.4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:sourcetree:3.4.13:*:*:*:*:macos:*:*",
                  "vulnerable": false
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. \n\t\n\tThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. \n\t\n\tAtlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\t\t\n\t\t* Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13\n\t\t\n\t\t\n\t\n\tSee the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). \n\t\n\tThis vulnerability was reported via our Bug Bounty program."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "RCE (Remote Code Execution)",
              "lang": "en",
              "type": "RCE (Remote Code Execution)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-21T17:00:00.501Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345"
        },
        {
          "url": "https://jira.atlassian.com/browse/SRCTREE-8275"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2026-21575",
    "datePublished": "2026-07-21T17:00:00.501Z",
    "dateReserved": "2026-01-01T00:00:40.720Z",
    "dateUpdated": "2026-07-24T03:55:49.714Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-21577 (GCVE-0-2026-21577)
Vulnerability from cvelistv5
Published
2026-07-21 17:00
Modified
2026-07-22 18:48
CWE
  • DoS (Denial of Service)
Summary
This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.
Impacted products
Vendor Product Version
Atlassian Confluence Data Center Version: 10.2.0 to 10.2.6
Version: 10.1.0 to 10.1.2
Version: 10.0.2 to 10.0.3
Version: 9.5.1 to 9.5.4
Version: 9.4.0 to 9.4.1
Version: 9.3.1 to 9.3.2
Version: 9.2.0 to 9.2.15
Version: 9.1.0 to 9.1.1
Version: 9.0.1 to 9.0.3
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-21577",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-22T18:32:38.139315Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-400",
                "description": "CWE-400 Uncontrolled Resource Consumption",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-22T18:48:52.568Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Confluence Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.0 to 10.2.6"
            },
            {
              "status": "affected",
              "version": "10.1.0 to 10.1.2"
            },
            {
              "status": "affected",
              "version": "10.0.2 to 10.0.3"
            },
            {
              "status": "affected",
              "version": "9.5.1 to 9.5.4"
            },
            {
              "status": "affected",
              "version": "9.4.0 to 9.4.1"
            },
            {
              "status": "affected",
              "version": "9.3.1 to 9.3.2"
            },
            {
              "status": "affected",
              "version": "9.2.0 to 9.2.15"
            },
            {
              "status": "affected",
              "version": "9.1.0 to 9.1.1"
            },
            {
              "status": "affected",
              "version": "9.0.1 to 9.0.3"
            },
            {
              "status": "unaffected",
              "version": "10.2.7 to 10.2.14"
            },
            {
              "status": "unaffected",
              "version": "9.2.17 to 9.2.22"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.4.1",
                  "versionStartIncluding": "9.4.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.3.2",
                  "versionStartIncluding": "9.3.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.2.15",
                  "versionStartIncluding": "9.2.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.1.1",
                  "versionStartIncluding": "9.1.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.0.3",
                  "versionStartIncluding": "9.0.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*",
                  "vulnerable": false
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center.\r\n\r\nThis DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17\r\n\r\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Penetration Testing program."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "DoS (Denial of Service)",
              "lang": "en",
              "type": "DoS (Denial of Service)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-21T17:00:00.483Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345"
        },
        {
          "url": "https://jira.atlassian.com/browse/CONFSERVER-104334"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2026-21577",
    "datePublished": "2026-07-21T17:00:00.483Z",
    "dateReserved": "2026-01-01T00:00:40.721Z",
    "dateUpdated": "2026-07-22T18:48:52.568Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-21579 (GCVE-0-2026-21579)
Vulnerability from cvelistv5
Published
2026-07-21 17:00
Modified
2026-07-22 18:48
CWE
  • Information Disclosure
Summary
This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.22 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.14 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Atlassian (Internal) program.
Impacted products
Vendor Product Version
Atlassian Confluence Data Center Version: 10.2.0 to 10.2.13
Version: 10.1.0 to 10.1.2
Version: 10.0.2 to 10.0.3
Version: 9.2.0 to 9.2.21
Version: 9.1.0 to 9.1.1
Version: 9.0.1 to 9.0.3
Version: 8.9.5 to 8.9.8
Version: 8.5.14 to 8.5.31
Version: 7.19.26 to 7.19.30
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-21579",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-22T18:33:05.618013Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-200",
                "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-22T18:48:58.801Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Confluence Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.0 to 10.2.13"
            },
            {
              "status": "affected",
              "version": "10.1.0 to 10.1.2"
            },
            {
              "status": "affected",
              "version": "10.0.2 to 10.0.3"
            },
            {
              "status": "affected",
              "version": "9.2.0 to 9.2.21"
            },
            {
              "status": "affected",
              "version": "9.1.0 to 9.1.1"
            },
            {
              "status": "affected",
              "version": "9.0.1 to 9.0.3"
            },
            {
              "status": "affected",
              "version": "8.9.5 to 8.9.8"
            },
            {
              "status": "affected",
              "version": "8.5.14 to 8.5.31"
            },
            {
              "status": "affected",
              "version": "7.19.26 to 7.19.30"
            },
            {
              "status": "unaffected",
              "version": "10.2.14"
            },
            {
              "status": "unaffected",
              "version": "9.2.22"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.2.21",
                  "versionStartIncluding": "9.2.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.1.1",
                  "versionStartIncluding": "9.1.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.0.3",
                  "versionStartIncluding": "9.0.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.9.8",
                  "versionStartIncluding": "8.9.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.5.31",
                  "versionStartIncluding": "8.5.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.25:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.26:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.27:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.28:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.29:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.30:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.31:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "7.19.30",
                  "versionStartIncluding": "7.19.26",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*",
                  "vulnerable": false
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center.\r\n\r\nThis Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.22\r\n\r\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.14\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Atlassian (Internal) program."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Information Disclosure",
              "lang": "en",
              "type": "Information Disclosure"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-21T17:00:00.404Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345"
        },
        {
          "url": "https://jira.atlassian.com/browse/CONFSERVER-104340"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2026-21579",
    "datePublished": "2026-07-21T17:00:00.404Z",
    "dateReserved": "2026-01-01T00:00:40.721Z",
    "dateUpdated": "2026-07-22T18:48:58.801Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-21571 (GCVE-0-2026-21571)
Vulnerability from cvelistv5
Published
2026-04-21 17:00
Modified
2026-04-23 03:56
CWE
  • OS Command Injection
Summary
This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.   This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H allows an authenticated attacker to execute commands on the remote system, which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.   Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bamboo Data Center 9.6.0: Upgrade to a release greater than or equal to 9.6.25 Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.18  Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.6 See the release notes ([https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]). You can download the latest version of Bamboo Data Center from the download center ([https://www.atlassian.com/software/bamboo/download-archives]).
Impacted products
Vendor Product Version
Atlassian Bamboo Data Center Version: 12.1.0 to 12.1.3
Version: 12.0.0 to 12.0.2
Version: 11.0.0 to 11.0.8
Version: 10.2.0 to 10.2.16
Version: 10.1.0 to 10.1.1
Version: 10.0.0 to 10.0.3
Version: 9.6.2 to 9.6.24
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-21571",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-04-22T00:00:00+00:00",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-78",
                "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-04-23T03:56:05.653Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Bamboo Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "12.1.0 to 12.1.3"
            },
            {
              "status": "affected",
              "version": "12.0.0 to 12.0.2"
            },
            {
              "status": "affected",
              "version": "11.0.0 to 11.0.8"
            },
            {
              "status": "affected",
              "version": "10.2.0 to 10.2.16"
            },
            {
              "status": "affected",
              "version": "10.1.0 to 10.1.1"
            },
            {
              "status": "affected",
              "version": "10.0.0 to 10.0.3"
            },
            {
              "status": "affected",
              "version": "9.6.2 to 9.6.24"
            },
            {
              "status": "unaffected",
              "version": "12.1.6"
            },
            {
              "status": "unaffected",
              "version": "10.2.18"
            },
            {
              "status": "unaffected",
              "version": "9.6.25"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "9.6.24",
                  "versionStartIncluding": "9.6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.6:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.7:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.8:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.9:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.10:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.11:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.12:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.13:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.14:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.15:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.16:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.17:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.18:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.19:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.20:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.21:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.22:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.23:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.24:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.25:*:*:*:data_center:*:*:*",
                  "vulnerable": false
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0,\r\n11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.\r\n\u00a0\r\nThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of\r\nCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H allows an authenticated attacker to execute commands\r\non the remote system, which has high impact to confidentiality, high impact to integrity, high impact to availability,\r\nand requires no user interaction.\r\n\u00a0\r\nAtlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade\r\nyour instance to one of the specified supported fixed versions:\r\n Bamboo Data Center 9.6.0: Upgrade to a release greater than or equal to 9.6.25\r\n Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.18\u00a0\r\n Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.6\r\n\r\nSee the release notes ([https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]). You can download the latest version of Bamboo Data Center from the download center ([https://www.atlassian.com/software/bamboo/download-archives])."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "OS Command Injection",
              "lang": "en",
              "type": "OS Command Injection"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-21T17:00:05.524Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1770913890"
        },
        {
          "url": "https://jira.atlassian.com/browse/BAM-26364"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2026-21571",
    "datePublished": "2026-04-21T17:00:05.524Z",
    "dateReserved": "2026-01-01T00:00:40.720Z",
    "dateUpdated": "2026-04-23T03:56:05.653Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-21570 (GCVE-0-2026-21570)
Vulnerability from cvelistv5
Published
2026-03-17 18:00
Modified
2026-03-17 18:21
CWE
  • RCE (Remote Code Execution)
Summary
This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.6, allows an authenticated attacker to execute malicious code on the remote system. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bamboo Data Center 9.6: Upgrade to a release greater than or equal to 9.6.24 Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.16 Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.3 See the release notes ([https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]). You can download the latest version of Bamboo Data Center from the download center ([https://www.atlassian.com/software/bamboo/download-archives]). This vulnerability was reported via our Atlassian (Internal) program.
Impacted products
Vendor Product Version
Atlassian Bamboo Data Center Version: 12.1.0 to 12.1.2
Version: 12.0.0 to 12.0.2
Version: 11.0.0 to 11.0.8
Version: 10.2.0 to 10.2.15
Version: 10.1.0 to 10.1.1
Version: 10.0.0 to 10.0.3
Version: 9.6.1 to 9.6.23
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-21570",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-03-17T18:21:29.754925Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-94",
                "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-03-17T18:21:46.118Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Bamboo Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "12.1.0 to 12.1.2"
            },
            {
              "status": "affected",
              "version": "12.0.0 to 12.0.2"
            },
            {
              "status": "affected",
              "version": "11.0.0 to 11.0.8"
            },
            {
              "status": "affected",
              "version": "10.2.0 to 10.2.15"
            },
            {
              "status": "affected",
              "version": "10.1.0 to 10.1.1"
            },
            {
              "status": "affected",
              "version": "10.0.0 to 10.0.3"
            },
            {
              "status": "affected",
              "version": "9.6.1 to 9.6.23"
            },
            {
              "status": "unaffected",
              "version": "12.1.3"
            },
            {
              "status": "unaffected",
              "version": "10.2.16"
            },
            {
              "status": "unaffected",
              "version": "9.6.24"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "9.6.23",
                  "versionStartIncluding": "9.6.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.6:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.7:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.8:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.9:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.10:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.11:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.12:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.13:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.14:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.15:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.16:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.17:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.18:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.19:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.20:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.21:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.22:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.23:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:bamboo:9.6.24:*:*:*:data_center:*:*:*",
                  "vulnerable": false
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity RCE (Remote Code Execution)\u00a0 vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.\r\n\r\nThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.6, allows an authenticated attacker to execute malicious code on the remote system.\r\n\r\nAtlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Bamboo Data Center 9.6: Upgrade to a release greater than or equal to 9.6.24\r\n\r\n Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.16\r\n\r\n Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.3\r\n\r\nSee the release notes ([https://confluence.atlassian.com/bambooreleases/bamboo-release-notes-1189793869.html]). You can download the latest version of Bamboo Data Center from the download center ([https://www.atlassian.com/software/bamboo/download-archives]).\r\n\r\nThis vulnerability was reported via our Atlassian (Internal) program."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "RCE (Remote Code Execution)",
              "lang": "en",
              "type": "RCE (Remote Code Execution)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-03-17T18:00:00.907Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1721271371"
        },
        {
          "url": "https://jira.atlassian.com/browse/BAM-26342"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2026-21570",
    "datePublished": "2026-03-17T18:00:00.907Z",
    "dateReserved": "2026-01-01T00:00:40.720Z",
    "dateUpdated": "2026-03-17T18:21:46.118Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-21569 (GCVE-0-2026-21569)
Vulnerability from cvelistv5
Published
2026-01-28 00:30
Modified
2026-01-28 14:49
CWE
  • XXE (XML External Entity Injection)
Summary
This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Crowd Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Crowd Data Center and Server 7.1: Upgrade to a release greater than or equal to 7.1.3 See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center and Server from the download center (https://www.atlassian.com/software/crowd/download-archive). This vulnerability was reported via our Atlassian (Internal) program.
Impacted products
Vendor Product Version
Atlassian Crowd Data Center Version: 7.1.0 to 7.1.2
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-21569",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-01-28T14:49:16.812896Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-611",
                "description": "CWE-611 Improper Restriction of XML External Entity Reference",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-01-28T14:49:56.282Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Crowd Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "7.1.0 to 7.1.2"
            },
            {
              "status": "unaffected",
              "version": "7.1.3"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. \n\t\n\tThis XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no user interaction. \n\t\n\tAtlassian recommends that Crowd Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\t\t\n\t\t* Crowd Data Center and Server 7.1: Upgrade to a release greater than or equal to 7.1.3\n\t\t\n\t\t\n\t\n\tSee the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center and Server from the download center (https://www.atlassian.com/software/crowd/download-archive). \n\t\n\tThis vulnerability was reported via our Atlassian (Internal) program."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "baseScore": 7.9,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "XXE (XML External Entity Injection)",
              "lang": "en",
              "type": "XXE (XML External Entity Injection)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-01-28T00:30:00.557Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1712324819"
        },
        {
          "url": "https://jira.atlassian.com/browse/CWD-6453"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2026-21569",
    "datePublished": "2026-01-28T00:30:00.557Z",
    "dateReserved": "2026-01-01T00:00:40.720Z",
    "dateUpdated": "2026-01-28T14:49:56.282Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2025-22178 (GCVE-0-2025-22178)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-22 17:21
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22178",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-22T17:21:18.410947Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-862",
                "description": "CWE-862 Missing Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-22T17:21:57.848Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the \"Why\" page."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:04.731Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8647"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22178",
    "datePublished": "2025-10-22T16:30:04.731Z",
    "dateReserved": "2025-01-01T00:01:27.178Z",
    "dateUpdated": "2025-10-22T17:21:57.848Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22169 (GCVE-0-2025-22169)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-22 17:24
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22169",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-22T17:23:53.628155Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-22T17:24:43.243Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:04.452Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8638"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22169",
    "datePublished": "2025-10-22T16:30:04.452Z",
    "dateReserved": "2025-01-01T00:01:27.176Z",
    "dateUpdated": "2025-10-22T17:24:43.243Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22173 (GCVE-0-2025-22173)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-22 19:12
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22173",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-22T19:12:13.342584Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-22T19:12:18.431Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:04.376Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8642"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22173",
    "datePublished": "2025-10-22T16:30:04.376Z",
    "dateReserved": "2025-01-01T00:01:27.177Z",
    "dateUpdated": "2025-10-22T19:12:18.431Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22170 (GCVE-0-2025-22170)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-22 19:16
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22170",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-22T19:16:03.345408Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-22T19:16:07.138Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:04.355Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8639"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22170",
    "datePublished": "2025-10-22T16:30:04.355Z",
    "dateReserved": "2025-01-01T00:01:27.177Z",
    "dateUpdated": "2025-10-22T19:16:07.138Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22174 (GCVE-0-2025-22174)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-22 19:39
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22174",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-22T19:39:21.470781Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-22T19:39:25.240Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:04.050Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8643"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22174",
    "datePublished": "2025-10-22T16:30:04.050Z",
    "dateReserved": "2025-01-01T00:01:27.177Z",
    "dateUpdated": "2025-10-22T19:39:25.240Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22172 (GCVE-0-2025-22172)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-23 17:32
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22172",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-23T17:32:37.765130Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-23T17:32:42.519Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:03.984Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8641"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22172",
    "datePublished": "2025-10-22T16:30:03.984Z",
    "dateReserved": "2025-01-01T00:01:27.177Z",
    "dateUpdated": "2025-10-23T17:32:42.519Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22176 (GCVE-0-2025-22176)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-23 17:40
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22176",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-23T17:40:44.569011Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-23T17:40:48.512Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:02.956Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8645"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22176",
    "datePublished": "2025-10-22T16:30:02.956Z",
    "dateReserved": "2025-01-01T00:01:27.177Z",
    "dateUpdated": "2025-10-23T17:40:48.512Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22171 (GCVE-0-2025-22171)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-23 18:11
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22171",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-23T18:11:49.143375Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-23T18:11:55.056Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:01.353Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8640"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22171",
    "datePublished": "2025-10-22T16:30:01.353Z",
    "dateReserved": "2025-01-01T00:01:27.177Z",
    "dateUpdated": "2025-10-23T18:11:55.056Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22168 (GCVE-0-2025-22168)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-24 14:45
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22168",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-24T14:45:17.604258Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-24T14:45:20.537Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user\u0027s private checklist."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:00.663Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8637"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22168",
    "datePublished": "2025-10-22T16:30:00.663Z",
    "dateReserved": "2025-01-01T00:01:27.176Z",
    "dateUpdated": "2025-10-24T14:45:20.537Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22177 (GCVE-0-2025-22177)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-22 18:48
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22177",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-22T18:48:37.219728Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-22T18:48:41.714Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:00.632Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8646"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22177",
    "datePublished": "2025-10-22T16:30:00.632Z",
    "dateReserved": "2025-01-01T00:01:27.177Z",
    "dateUpdated": "2025-10-22T18:48:41.714Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22175 (GCVE-0-2025-22175)
Vulnerability from cvelistv5
Published
2025-10-22 16:30
Modified
2025-10-27 16:09
CWE
  • Improper Authorization
Summary
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
Impacted products
Vendor Product Version
Atlassian Jira Align Version: >= 11.14.0
Version: >= 11.14.1
Version: >= 11.15.0
Version: >= 11.15.1
Version: >= 11.16.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22175",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-22T18:08:17.435004Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-285",
                "description": "CWE-285 Improper Authorization",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-27T16:09:06.998Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Align",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.14.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.15.1"
            },
            {
              "status": "affected",
              "version": "\u003e= 11.16.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 11.16.1"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Frank Lycops, NATO Cyber Security Centre"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user\u0027s private checklist."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Improper Authorization",
              "lang": "en",
              "type": "Improper Authorization"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T16:30:00.592Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/JIRAALIGN-8644"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22175",
    "datePublished": "2025-10-22T16:30:00.592Z",
    "dateReserved": "2025-01-01T00:01:27.177Z",
    "dateUpdated": "2025-10-27T16:09:06.998Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22167 (GCVE-0-2025-22167)
Vulnerability from cvelistv5
Published
2025-10-22 01:00
Modified
2026-02-26 16:57
CWE
  • Path Traversal (Arbitrary Read/Write)
Summary
This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by the Jira JVM process. Atlassian recommends that Jira Software Data Center and Server customers upgrade to the latest version; if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Jira Software Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.28 Jira Software Data Center and Server 10.3: Upgrade to a release greater than or equal to 10.3.12 Jira Software Data Center and Server 11.0: Upgrade to a release greater than or equal to 11.1.0 See the release notes. You can download the latest version of Jira Software Data Center and Server from the download center. This vulnerability was reported via our Atlassian (Internal) program.
Impacted products
Vendor Product Version
Atlassian Jira Software Data Center Version: 11.0.0 to 11.0.1
Version: 10.3.0 to 10.3.11
Version: 9.12.0 to 9.12.27
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22167",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-23T03:55:21.503912Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-22",
                "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-02-26T16:57:14.161Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Software Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0 to 11.0.1"
            },
            {
              "status": "affected",
              "version": "10.3.0 to 10.3.11"
            },
            {
              "status": "affected",
              "version": "9.12.0 to 9.12.27"
            },
            {
              "status": "unaffected",
              "version": "11.1.0 to 11.1.1"
            },
            {
              "status": "unaffected",
              "version": "10.3.12"
            },
            {
              "status": "unaffected",
              "version": "9.12.28"
            }
          ]
        },
        {
          "product": "Jira Software Server",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "9.12.0 to 9.12.27"
            },
            {
              "status": "unaffected",
              "version": "9.12.28"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by the Jira JVM process. Atlassian recommends that Jira Software Data Center and Server customers upgrade to the latest version; if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Jira Software Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.28\r\n Jira Software Data Center and Server 10.3: Upgrade to a release greater than or equal to 10.3.12\r\n Jira Software Data Center and Server 11.0: Upgrade to a release greater than or equal to 11.1.0\r\n\r\nSee the release notes. You can download the latest version of Jira Software Data Center and Server from the download center. This vulnerability was reported via our Atlassian (Internal) program."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Path Traversal (Arbitrary Read/Write)",
              "lang": "en",
              "type": "Path Traversal (Arbitrary Read/Write)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-22T01:00:06.278Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1652920034"
        },
        {
          "url": "https://jira.atlassian.com/browse/JSWSERVER-26552"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22167",
    "datePublished": "2025-10-22T01:00:06.278Z",
    "dateReserved": "2025-01-01T00:01:27.176Z",
    "dateUpdated": "2026-02-26T16:57:14.161Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2025-22166 (GCVE-0-2025-22166)
Vulnerability from cvelistv5
Published
2025-10-21 16:00
Modified
2025-10-21 16:21
CWE
  • DoS (Denial of Service)
Summary
This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.25 Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.7 Confluence Data Center and Server 10.0: Upgrade to a release greater than or equal to 10.0.2 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Atlassian (Internal) program.
Impacted products
Vendor Product Version
Atlassian Confluence Data Center Version: 9.5.1 to 9.5.4
Version: 9.4.0 to 9.4.1
Version: 9.3.1 to 9.3.2
Version: 9.2.0 to 9.2.6
Version: 9.1.0 to 9.1.1
Version: 9.0.1 to 9.0.3
Version: 8.9.0 to 8.9.8
Version: 8.8.0 to 8.8.1
Version: 8.7.1 to 8.7.2
Version: 8.6.1 to 8.6.2
Version: 8.5.3 to 8.5.24
Version: 7.19.16 to 7.19.30
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22166",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-10-21T16:21:21.142041Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-405",
                "description": "CWE-405 Asymmetric Resource Consumption (Amplification)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-10-21T16:21:27.828Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Confluence Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "9.5.1 to 9.5.4"
            },
            {
              "status": "affected",
              "version": "9.4.0 to 9.4.1"
            },
            {
              "status": "affected",
              "version": "9.3.1 to 9.3.2"
            },
            {
              "status": "affected",
              "version": "9.2.0 to 9.2.6"
            },
            {
              "status": "affected",
              "version": "9.1.0 to 9.1.1"
            },
            {
              "status": "affected",
              "version": "9.0.1 to 9.0.3"
            },
            {
              "status": "affected",
              "version": "8.9.0 to 8.9.8"
            },
            {
              "status": "affected",
              "version": "8.8.0 to 8.8.1"
            },
            {
              "status": "affected",
              "version": "8.7.1 to 8.7.2"
            },
            {
              "status": "affected",
              "version": "8.6.1 to 8.6.2"
            },
            {
              "status": "affected",
              "version": "8.5.3 to 8.5.24"
            },
            {
              "status": "affected",
              "version": "7.19.16 to 7.19.30"
            },
            {
              "status": "unaffected",
              "version": "10.0.2 to 10.0.3"
            },
            {
              "status": "unaffected",
              "version": "9.2.7 to 9.2.9"
            },
            {
              "status": "unaffected",
              "version": "8.5.25 to 8.5.27"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.4.1",
                  "versionStartIncluding": "9.4.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.3.2",
                  "versionStartIncluding": "9.3.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.2.6",
                  "versionStartIncluding": "9.2.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.1.1",
                  "versionStartIncluding": "9.1.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "9.0.3",
                  "versionStartIncluding": "9.0.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.9.8",
                  "versionStartIncluding": "8.9.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.8.1",
                  "versionStartIncluding": "8.8.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.7.2",
                  "versionStartIncluding": "8.7.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.6.2",
                  "versionStartIncluding": "8.6.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "8.5.24",
                  "versionStartIncluding": "8.5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.13:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "7.19.30",
                  "versionStartIncluding": "7.19.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.25:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.26:*:*:*:*:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.27:*:*:*:*:*:*:*",
                  "vulnerable": false
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.\r\n\r\nThis DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.25\r\n Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.7\r\n Confluence Data Center and Server 10.0: Upgrade to a release greater than or equal to 10.0.2\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Atlassian (Internal) program."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "DoS (Denial of Service)",
              "lang": "en",
              "type": "DoS (Denial of Service)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-21T16:00:05.978Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1652920034"
        },
        {
          "url": "https://jira.atlassian.com/browse/CONFSERVER-100907"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22166",
    "datePublished": "2025-10-21T16:00:05.978Z",
    "dateReserved": "2025-01-01T00:01:27.176Z",
    "dateUpdated": "2025-10-21T16:21:27.828Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2025-22165 (GCVE-0-2025-22165)
Vulnerability from cvelistv5
Published
2025-07-24 22:30
Modified
2026-02-26 17:50
CWE
  • Security Misconfiguration
Summary
This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.  Atlassian recommends that Sourcetree for Mac users upgrade to the latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://www.sourcetreeapp.com/download-archives . You can download the latest version of Sourcetree for Mac from the download center https://www.sourcetreeapp.com/download-archives . This vulnerability was found through the Atlassian Bug Bounty Program by Karol Mazurek (AFINE).
Impacted products
Vendor Product Version
Atlassian Sourcetree for Mac Version: All versions from 4.2.8 to 4.2.11 inclusive
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22165",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-07-29T03:55:17.784273Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-269",
                "description": "CWE-269 Improper Privilege Management",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-02-26T17:50:14.849Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Sourcetree for Mac",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "All versions from 4.2.8 to 4.2.11 inclusive"
            },
            {
              "status": "unaffected",
              "version": "All versions from 4.2.12"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:atlassian:sourcetree:*:*:*:*:*:macos:*:*",
                  "versionEndExcluding": "4.2.12",
                  "versionStartIncluding": "4.2.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:sourcetree:4.2.12:*:*:*:*:macos:*:*",
                  "vulnerable": false
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Karol Mazurek (AFINE)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac.\n\nThis ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.\u00a0\n\nAtlassian recommends that Sourcetree for Mac users upgrade to the latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://www.sourcetreeapp.com/download-archives .\n\nYou can download the latest version of Sourcetree for Mac from the download center https://www.sourcetreeapp.com/download-archives .\n\nThis vulnerability was found through the Atlassian Bug Bounty Program by Karol Mazurek (AFINE)."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:H/SI:H/SA:L",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Security Misconfiguration",
              "lang": "en",
              "type": "Security Misconfiguration"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-07-24T22:30:00.776Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/SRCTREE-8217"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22165",
    "datePublished": "2025-07-24T22:30:00.776Z",
    "dateReserved": "2025-01-01T00:01:27.176Z",
    "dateUpdated": "2026-02-26T17:50:14.849Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2025-22157 (GCVE-0-2025-22157)
Vulnerability from cvelistv5
Published
2025-05-20 18:00
Modified
2026-02-26 18:28
CWE
  • PrivEsc (Privilege Escalation)
Summary
This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. Atlassian recommends that Jira Core Data Center and Server and Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Jira Core Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.20 Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.20 Jira Core Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5 Jira Service Management Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5 Jira Core Data Center 10.4: Upgrade to a release greater than or equal to 10.6.0 Jira Service Management Data Center 10.4: Upgrade to a release greater than or equal to 10.6.0 Jira Core Data Center 10.5: Upgrade to a release greater than or equal to 10.5.1 Jira Service Management Data Center 10.5: Upgrade to a release greater than or equal to 10.5.1 See the release notes. You can download the latest version of Jira Core Data Center and Jira Service Management Data Center from the download center. This vulnerability was reported via our Atlassian (Internal) program.
Impacted products
Vendor Product Version
Atlassian Jira Core Data Center Version: 10.5.0
Version: 10.4.0 to 10.4.1
Version: 10.3.0 to 10.3.4
Version: 9.12.0 to 9.12.19
Create a notification for this product.
   Atlassian Jira Core Server Version: 9.12.0 to 9.12.19
Create a notification for this product.
   Atlassian Jira Service Management Data Center Version: 10.5.0
Version: 10.4.0 to 10.4.1
Version: 10.3.0 to 10.3.4
Version: 5.12.0 to 5.12.19
Create a notification for this product.
   Atlassian Jira Service Management Server Version: 5.12.0 to 5.12.19
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-22157",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-05-21T03:55:33.263670Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-284",
                "description": "CWE-284 Improper Access Control",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-02-26T18:28:05.031Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Core Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "10.5.0"
            },
            {
              "status": "affected",
              "version": "10.4.0 to 10.4.1"
            },
            {
              "status": "affected",
              "version": "10.3.0 to 10.3.4"
            },
            {
              "status": "affected",
              "version": "9.12.0 to 9.12.19"
            },
            {
              "status": "unaffected",
              "version": "10.6.0"
            },
            {
              "status": "unaffected",
              "version": "10.5.1"
            },
            {
              "status": "unaffected",
              "version": "10.3.5 to 10.3.6"
            },
            {
              "status": "unaffected",
              "version": "9.12.22 to 9.12.23"
            }
          ]
        },
        {
          "product": "Jira Core Server",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "9.12.0 to 9.12.19"
            },
            {
              "status": "unaffected",
              "version": "9.12.22 to 9.12.23"
            }
          ]
        },
        {
          "product": "Jira Service Management Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "10.5.0"
            },
            {
              "status": "affected",
              "version": "10.4.0 to 10.4.1"
            },
            {
              "status": "affected",
              "version": "10.3.0 to 10.3.4"
            },
            {
              "status": "affected",
              "version": "5.12.0 to 5.12.19"
            },
            {
              "status": "unaffected",
              "version": "10.6.0"
            },
            {
              "status": "unaffected",
              "version": "10.5.1"
            },
            {
              "status": "unaffected",
              "version": "10.3.5 to 10.3.6"
            },
            {
              "status": "unaffected",
              "version": "5.12.22 to 5.12.23"
            }
          ]
        },
        {
          "product": "Jira Service Management Server",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "5.12.0 to 5.12.19"
            },
            {
              "status": "unaffected",
              "version": "5.12.22 to 5.12.23"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:10.5.0:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "10.4.1",
                  "versionStartIncluding": "10.4.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "10.3.4",
                  "versionStartIncluding": "10.3.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "9.12.19",
                  "versionStartIncluding": "9.12.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:10.6.0:*:*:*:data_center:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:10.5.1:*:*:*:data_center:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "10.3.6",
                  "versionStartIncluding": "10.3.5",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "9.12.23",
                  "versionStartIncluding": "9.12.22",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:*:*:*:*:server:*:*:*",
                  "versionEndIncluding": "9.12.19",
                  "versionStartIncluding": "9.12.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_core:*:*:*:*:server:*:*:*",
                  "versionEndIncluding": "9.12.23",
                  "versionStartIncluding": "9.12.22",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:10.5.0:*:*:*:data_center:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "10.4.1",
                  "versionStartIncluding": "10.4.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "10.3.4",
                  "versionStartIncluding": "10.3.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "5.12.19",
                  "versionStartIncluding": "5.12.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:10.6.0:*:*:*:data_center:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:10.5.1:*:*:*:data_center:*:*:*",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "10.3.6",
                  "versionStartIncluding": "10.3.5",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*",
                  "versionEndIncluding": "5.12.23",
                  "versionStartIncluding": "5.12.22",
                  "vulnerable": false
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*",
                  "versionEndIncluding": "5.12.19",
                  "versionStartIncluding": "5.12.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*",
                  "versionEndIncluding": "5.12.23",
                  "versionStartIncluding": "5.12.22",
                  "vulnerable": false
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Internal (Atlassian)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions:\n\n9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server\n\n5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server\n\nThis PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. \n\nAtlassian recommends that Jira Core Data Center and Server and Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\nJira Core Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.20\n\nJira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.20\n\nJira Core Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5\n\nJira Service Management Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5\n\nJira Core Data Center 10.4: Upgrade to a release greater than or equal to 10.6.0\n\nJira Service Management Data Center 10.4: Upgrade to a release greater than or equal to 10.6.0\n\nJira Core Data Center 10.5: Upgrade to a release greater than or equal to 10.5.1\n\nJira Service Management Data Center 10.5: Upgrade to a release greater than or equal to 10.5.1\n\nSee the release notes. You can download the latest version of Jira Core Data Center and Jira Service Management Data Center from the download center. \n\nThis vulnerability was reported via our Atlassian (Internal) program."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "PrivEsc (Privilege Escalation)",
              "lang": "en",
              "type": "PrivEsc (Privilege Escalation)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-05-20T18:00:01.328Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1561365992"
        },
        {
          "url": "https://jira.atlassian.com/browse/JRASERVER-78766"
        },
        {
          "url": "https://jira.atlassian.com/browse/JSDSERVER-16206"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2025-22157",
    "datePublished": "2025-05-20T18:00:01.328Z",
    "dateReserved": "2025-01-01T00:01:27.175Z",
    "dateUpdated": "2026-02-26T18:28:05.031Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2023-22514 (GCVE-0-2023-22514)
Vulnerability from cvelistv5
Published
2025-03-18 17:03
Modified
2025-05-12 15:40
CWE
  • RCE (Remote Code Execution)
Summary
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vector of: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H which allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.15 See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). This vulnerability was reported via our Penetration Testing program.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-22514",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-05-12T15:40:08.894218Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-94",
                "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-05-12T15:40:34.777Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Sourcetree for Mac",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 3.4.14"
            },
            {
              "status": "affected",
              "version": "\u003e= 3.4.14"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 3.4.15"
            }
          ]
        },
        {
          "product": "Sourcetree for Windows",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 3.4.14"
            },
            {
              "status": "affected",
              "version": "\u003e= 3.4.14"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 3.4.15"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. \r\n\t\r\n\tThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vector of: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H which allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. \r\n\t\r\n\tAtlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n\t\t\r\n\t\tSourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.15\r\n\t\t\r\n\t\t\r\n\t\r\n\tSee the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). \r\n\t\r\n\tThis vulnerability was reported via our Penetration Testing program."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "RCE (Remote Code Execution)",
              "lang": "en",
              "type": "RCE (Remote Code Execution)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-03-18T17:03:59.441Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1299929380"
        },
        {
          "url": "https://jira.atlassian.com/browse/SRCTREE-8076"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2023-22514",
    "datePublished": "2025-03-18T17:03:59.441Z",
    "dateReserved": "2023-01-01T00:01:22.330Z",
    "dateUpdated": "2025-05-12T15:40:34.777Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2023-22512 (GCVE-0-2023-22512)
Vulnerability from cvelistv5
Published
2025-03-17 22:34
Modified
2025-05-12 15:39
CWE
  • DoS (Denial of Service)
Summary
This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.14 Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.1 Confluence Data Center and Server 8.6 or above: No need to upgrade, you're already on a patched version See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ]). This vulnerability was reported via our Bug Bounty program.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-22512",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-05-12T15:38:47.977501Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-400",
                "description": "CWE-400 Uncontrolled Resource Consumption",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-05-12T15:39:27.035Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Confluence Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 5.6.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 5.6.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 7.19.13"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 7.19.14"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 8.5.1"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 8.6.0"
            }
          ]
        },
        {
          "product": "Confluence Server",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "\u003c 5.6.0"
            },
            {
              "status": "affected",
              "version": "\u003e= 5.6.0"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 7.19.13"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 7.19.14"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 8.5.1"
            },
            {
              "status": "unaffected",
              "version": "\u003e= 8.6.0"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.14 Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.1 Confluence Data Center and Server 8.6 or above: No need to upgrade, you\u0027re already on a patched version See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ]). This vulnerability was reported via our Bug Bounty program."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "DoS (Denial of Service)",
              "lang": "en",
              "type": "DoS (Denial of Service)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-03-17T22:34:42.950Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1283691616"
        },
        {
          "url": "https://jira.atlassian.com/browse/CONFSERVER-91258"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2023-22512",
    "datePublished": "2025-03-17T22:34:42.950Z",
    "dateReserved": "2023-01-01T00:01:22.330Z",
    "dateUpdated": "2025-05-12T15:39:27.035Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2019-15002 (GCVE-0-2019-15002)
Vulnerability from cvelistv5
Published
2025-02-11 17:24
Modified
2025-03-13 14:15
CWE
  • Cross-Site Request Forgery
Summary
An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.
References
Impacted products
Vendor Product Version
Atlassian Jira Server Patch: unspecified   < 7.6.4
Version: unspecified   < 8.1.0
Create a notification for this product.
   Atlassian Jira Data Center Patch: unspecified   < 7.6.4
Version: unspecified   < 8.1.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "NONE",
              "baseScore": 4.3,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "LOW",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2019-15002",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-02-28T20:49:41.973789Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-352",
                "description": "CWE-352 Cross-Site Request Forgery (CSRF)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-03-13T14:15:39.823Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Jira Server",
          "vendor": "Atlassian",
          "versions": [
            {
              "lessThan": "7.6.4",
              "status": "unaffected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "8.1.0",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "Jira Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "lessThan": "7.6.4",
              "status": "unaffected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "8.1.0",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ],
      "datePublic": "2019-09-16T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn\u2019t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Cross-Site Request Forgery",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-02-11T17:24:15.763Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://jira.atlassian.com/browse/JRASERVER-67979"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2019-15002",
    "datePublished": "2025-02-11T17:24:15.763Z",
    "dateReserved": "2019-08-13T00:00:00.000Z",
    "dateUpdated": "2025-03-13T14:15:39.823Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2024-21703 (GCVE-0-2024-21703)
Vulnerability from cvelistv5
Published
2024-11-27 17:00
Modified
2024-11-27 17:33
CWE
  • Security Misconfiguration
Summary
This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about the Confluence Data Center configuration which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to the latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.18 * Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.5 * Confluence Data Center and Server 8.7: Upgrade to a release greater than or equal to 8.7.2 * Confluence Data Center and Server 8.8: Upgrade to a release greater than or equal to 8.8.0 See the release notes (https://confluence.atlassian.com/conf88/confluence-release-notes-1354501008.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ). This vulnerability was reported via our Atlassian Bug Bounty Program by Chris Elliot.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "cpes": [
              "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "product": "confluence_data_center",
            "vendor": "atlassian",
            "versions": [
              {
                "lessThan": "7.1918",
                "status": "affected",
                "version": "7.19",
                "versionType": "custom"
              },
              {
                "lessThan": "8.5.5",
                "status": "affected",
                "version": "8.5",
                "versionType": "custom"
              },
              {
                "lessThan": "8.7.2",
                "status": "affected",
                "version": "8.7",
                "versionType": "custom"
              },
              {
                "lessThan": "8.8.0",
                "status": "affected",
                "version": "8.8",
                "versionType": "custom"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "product": "confluence_server",
            "vendor": "atlassian",
            "versions": [
              {
                "lessThan": "7.19.18",
                "status": "affected",
                "version": "7.19",
                "versionType": "custom"
              },
              {
                "lessThan": "8.5.5",
                "status": "affected",
                "version": "8.5",
                "versionType": "custom"
              },
              {
                "lessThan": "8.7.2",
                "status": "affected",
                "version": "8.7",
                "versionType": "custom"
              },
              {
                "lessThan": "8.8.0",
                "status": "affected",
                "version": "8.8",
                "versionType": "custom"
              }
            ]
          }
        ],
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "HIGH",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 6.4,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "HIGH",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-21703",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-11-27T17:24:22.500451Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-732",
                "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-11-27T17:33:53.585Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Confluence Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "8.7.1"
            },
            {
              "status": "unaffected",
              "version": "8.8.0 to 8.8.1"
            },
            {
              "status": "unaffected",
              "version": "8.7.2"
            },
            {
              "status": "unaffected",
              "version": "8.5.5 to 8.5.17"
            },
            {
              "status": "unaffected",
              "version": "7.19.18 to 7.19.29"
            }
          ]
        },
        {
          "product": "Confluence Server",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "unaffected",
              "version": "8.5.5 to 8.5.17"
            },
            {
              "status": "unaffected",
              "version": "7.19.18 to 7.19.29"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Chris Elliot"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations.\n\n\n\nThis Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about the Confluence Data Center configuration which has high impact to confidentiality, high impact to integrity,  high impact to availability, and no user interaction.\n\n\n\nAtlassian recommends that Confluence Data Center and Server customers upgrade to the latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\n* Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.18 \n* Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.5\n* Confluence Data Center and Server 8.7: Upgrade to a release greater than or equal to 8.7.2\n* Confluence Data Center and Server 8.8: Upgrade to a release greater than or equal to 8.8.0\n\n\n\nSee the release notes (https://confluence.atlassian.com/conf88/confluence-release-notes-1354501008.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ). \n\nThis vulnerability was reported via our Atlassian Bug Bounty Program by Chris Elliot."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Security Misconfiguration",
              "lang": "en",
              "type": "Security Misconfiguration"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-11-27T17:00:01.507Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://jira.atlassian.com/browse/CONFSERVER-98413"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2024-21703",
    "datePublished": "2024-11-27T17:00:01.507Z",
    "dateReserved": "2024-01-01T00:05:33.849Z",
    "dateUpdated": "2024-11-27T17:33:53.585Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2024-21697 (GCVE-0-2024-21697)
Vulnerability from cvelistv5
Published
2024-11-19 19:00
Modified
2024-11-25 14:04
CWE
  • RCE (Remote Code Execution)
Summary
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Sourcetree for Mac 4.2: Upgrade to a release greater than or equal to 4.2.9 Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.20 See the release notes ([https://www.sourcetreeapp.com/download-archives]). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center ([https://www.sourcetreeapp.com/download-archives]). This vulnerability was reported via our Penetration Testing program.
Impacted products
Vendor Product Version
Atlassian Sourcetree for Mac Version: All versions from 4.2.8 to 4.2.8
Create a notification for this product.
   Atlassian Sourcetree for Windows Version: All versions from 3.4.19 to 3.4.19
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "cpes": [
              "cpe:2.3:a:atlassian:sourcetree:*:*:*:*:*:macos:*:*"
            ],
            "defaultStatus": "unknown",
            "product": "sourcetree",
            "vendor": "atlassian",
            "versions": [
              {
                "lessThan": "4.2.9",
                "status": "affected",
                "version": "4.2.8",
                "versionType": "custom"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:atlassian:sourcetree:*:*:*:*:*:windows:*:*"
            ],
            "defaultStatus": "unknown",
            "product": "sourcetree",
            "vendor": "atlassian",
            "versions": [
              {
                "lessThan": "3.4.20",
                "status": "affected",
                "version": "3.4.19",
                "versionType": "custom"
              }
            ]
          }
        ],
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-21697",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-11-23T04:55:49.200583Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-11-25T14:04:49.167Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Sourcetree for Mac",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "All versions from 4.2.8 to 4.2.8"
            },
            {
              "status": "unaffected",
              "version": "All versions from 4.2.9"
            }
          ]
        },
        {
          "product": "Sourcetree for Windows",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "All versions from 3.4.19 to 3.4.19"
            },
            {
              "status": "unaffected",
              "version": "All versions from 3.4.20"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows.\r\n\r\nThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.\r\n\r\nAtlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Sourcetree for Mac 4.2: Upgrade to a release greater than or equal to 4.2.9\r\n Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.20\r\n\r\nSee the release notes ([https://www.sourcetreeapp.com/download-archives]). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center ([https://www.sourcetreeapp.com/download-archives]).\r\n\r\nThis vulnerability was reported via our Penetration Testing program."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "RCE (Remote Code Execution)",
              "lang": "en",
              "type": "RCE (Remote Code Execution)"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-11-19T19:00:00.635Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1456179091"
        },
        {
          "url": "https://jira.atlassian.com/browse/SRCTREE-8168"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2024-21697",
    "datePublished": "2024-11-19T19:00:00.635Z",
    "dateReserved": "2024-01-01T00:05:33.848Z",
    "dateUpdated": "2024-11-25T14:04:49.167Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2024-21690 (GCVE-0-2024-21690)
Vulnerability from cvelistv5
Published
2024-08-21 16:05
Modified
2024-11-06 18:47
CWE
  • Reflected XSS
Summary
This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. This Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability, with a CVSS Score of 7.1, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser and force a end user to execute unwanted actions on a web application in which they're currently authenticated which has high impact to confidentiality, low impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.26 * Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.14 * Confluence Data Center and Server 9.0: Upgrade to a release greater than or equal to 9.0.1 See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives). This vulnerability was reported via our Bug Bounty program.
Impacted products
Vendor Product Version
Atlassian Confluence Data Center Version: 8.9.0 to 8.9.5
Version: 8.8.0 to 8.8.1
Version: 8.7.1 to 8.7.2
Version: 8.6.0 to 8.6.2
Version: 8.5.0 to 8.5.12
Version: 8.4.0 to 8.4.5
Version: 8.3.0 to 8.3.4
Version: 8.2.0 to 8.2.3
Version: 8.1.0 to 8.1.4
Version: 8.0.0 to 8.0.4
Version: 7.20.0 to 7.20.3
Create a notification for this product.
   Atlassian Confluence Server Version: 8.5.0 to 8.5.12
Version: 8.4.0 to 8.4.5
Version: 8.3.0 to 8.3.4
Version: 8.2.0 to 8.2.3
Version: 8.1.0 to 8.1.4
Version: 8.0.0 to 8.0.4
Version: 7.20.0 to 7.20.3
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-21690",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-08-22T13:51:34.740469Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-79",
                "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-11-06T18:47:21.992Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Confluence Data Center",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "8.9.0 to 8.9.5"
            },
            {
              "status": "affected",
              "version": "8.8.0 to 8.8.1"
            },
            {
              "status": "affected",
              "version": "8.7.1 to 8.7.2"
            },
            {
              "status": "affected",
              "version": "8.6.0 to 8.6.2"
            },
            {
              "status": "affected",
              "version": "8.5.0 to 8.5.12"
            },
            {
              "status": "affected",
              "version": "8.4.0 to 8.4.5"
            },
            {
              "status": "affected",
              "version": "8.3.0 to 8.3.4"
            },
            {
              "status": "affected",
              "version": "8.2.0 to 8.2.3"
            },
            {
              "status": "affected",
              "version": "8.1.0 to 8.1.4"
            },
            {
              "status": "affected",
              "version": "8.0.0 to 8.0.4"
            },
            {
              "status": "affected",
              "version": "7.20.0 to 7.20.3"
            },
            {
              "status": "unaffected",
              "version": "9.0.1 to 9.0.2"
            },
            {
              "status": "unaffected",
              "version": "8.5.14"
            },
            {
              "status": "unaffected",
              "version": "7.19.26"
            }
          ]
        },
        {
          "product": "Confluence Server",
          "vendor": "Atlassian",
          "versions": [
            {
              "status": "affected",
              "version": "8.5.0 to 8.5.12"
            },
            {
              "status": "affected",
              "version": "8.4.0 to 8.4.5"
            },
            {
              "status": "affected",
              "version": "8.3.0 to 8.3.4"
            },
            {
              "status": "affected",
              "version": "8.2.0 to 8.2.3"
            },
            {
              "status": "affected",
              "version": "8.1.0 to 8.1.4"
            },
            {
              "status": "affected",
              "version": "8.0.0 to 8.0.4"
            },
            {
              "status": "affected",
              "version": "7.20.0 to 7.20.3"
            },
            {
              "status": "unaffected",
              "version": "8.5.14"
            },
            {
              "status": "unaffected",
              "version": "7.19.26"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. \n\t\n\tThis Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability, with a CVSS Score of 7.1, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser and force a end user to execute unwanted actions on a web application in which they\u0027re currently authenticated which has high impact to confidentiality, low impact to integrity, no impact to availability, and requires user interaction. \n\t\n\tAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\t\t\n\t\t* Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.26\n\t\t\n\t\t* Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.14\n\t\t\n\t\t* Confluence Data Center and Server 9.0: Upgrade to a release greater than or equal to 9.0.1\n\t\t\n\t\t\n\t\n\tSee the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives). \n\t\n\tThis vulnerability was reported via our Bug Bounty program."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Reflected XSS",
              "lang": "en",
              "type": "Reflected XSS"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-08-21T17:00:02.995Z",
        "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "shortName": "atlassian"
      },
      "references": [
        {
          "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1431535667"
        },
        {
          "url": "https://jira.atlassian.com/browse/CONFSERVER-97720"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
    "assignerShortName": "atlassian",
    "cveId": "CVE-2024-21690",
    "datePublished": "2024-08-21T16:05:00.394Z",
    "dateReserved": "2024-01-01T00:05:33.847Z",
    "dateUpdated": "2024-11-06T18:47:21.992Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}