cbcvebase.
CVE-2017-14591
published 2017-11-29

CVE-2017-14591: Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories…

critical9CVSS 3.0
AVNACHPRNUINSCCHIHAH
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.

Affected

5 ranges
VendorProductVersion rangeFixed in
atlassiancrucible< 4.4.34.4.3
atlassiancrucible
atlassianfisheye< 4.4.34.4.3
atlassianfisheye
atlassianfisheye_and_crucible