CVE-2020-4013

Severity
5.4MEDIUM
EPSS
0.2%
top 55.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateMay 24

Description

The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages4 packages

CVEListV5atlassian/fisheyeunspecified4.8.1
NVDatlassian/fisheye< 4.8.1
CVEListV5atlassian/crucibleunspecified4.8.1
NVDatlassian/crucible< 4.8.1

🔴Vulnerability Details

2
GHSA
GHSA-4256-46gj-h2fm: The review resource in Atlassian Fisheye and Crucible before version 42022-05-24
CVEList
CVE-2020-4013: The review resource in Atlassian Fisheye and Crucible before version 42020-06-01
CVE-2020-4013 (MEDIUM CVSS 5.4) | The review resource in Atlassian Fi | cvebase.io