cbcvebase.
CVE-2018-5228
published 2018-04-24

CVE-2018-5228: The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross…

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.

Affected

3 ranges
VendorProductVersion rangeFixed in
atlassiancrucible< 4.5.34.5.3
atlassianfisheye< 4.5.34.5.3
atlassianfisheye_and_crucible>= unspecified < 4.5.34.5.3