CVE-2020-4018

Severity
8.8HIGH
EPSS
0.2%
top 63.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateMay 24

Description

The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5atlassian/fisheyeunspecified4.8.1
NVDatlassian/fisheye< 4.8.1
CVEListV5atlassian/crucibleunspecified4.8.1
NVDatlassian/crucible< 4.8.1

🔴Vulnerability Details

2
GHSA
GHSA-p24q-jv27-xq4x: The setup resources in Atlassian Fisheye and Crucible before version 42022-05-24
CVEList
CVE-2020-4018: The setup resources in Atlassian Fisheye and Crucible before version 42020-06-01
CVE-2020-4018 (HIGH CVSS 8.8) | The setup resources in Atlassian Fi | cvebase.io