CVE-2019-15009Atlassian Crucible vulnerability

3 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 51.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 24

Description

The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

CVEListV5atlassian/fisheyeunspecified4.8.0
NVDatlassian/fisheye< 4.8.0
CVEListV5atlassian/crucibleunspecified4.8.0
NVDatlassian/crucible< 4.8.0

🔴Vulnerability Details

2
GHSA
GHSA-hpg6-j356-pfwf: The /json/profile/removeStarAjax2022-05-24
CVEList
CVE-2019-15009: The /json/profile/removeStarAjax2019-12-11
CVE-2019-15009 — Atlassian Crucible vulnerability | cvebase