CVE-2018-13399

Severity
7.8HIGH
EPSS
0.0%
top 93.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 13

Description

The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5atlassian/fisheye_and_crucibleunspecified4.6.1
NVDatlassian/fisheye< 4.6.1
NVDatlassian/crucible< 4.6.1

🔴Vulnerability Details

2
GHSA
GHSA-7xhf-frpm-r9fm: The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 42022-05-13
CVEList
CVE-2018-13399: The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 42018-10-16
CVE-2018-13399 (HIGH CVSS 7.8) | The Microsoft Windows Installer for | cvebase.io