cbcvebase.
CVE-2018-13398
published 2018-09-18

CVE-2018-13398: The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a…

medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.

Affected

3 ranges
VendorProductVersion rangeFixed in
atlassiancrucible< 4.5.44.5.4
atlassianfisheye< 4.5.44.5.4
atlassianfisheye_and_crucible>= unspecified < 4.5.44.5.4