CVE-2020-4023

Severity
5.4MEDIUM
EPSS
0.3%
top 43.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateMay 24

Description

The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages4 packages

CVEListV5atlassian/fisheyeunspecified4.8.2
NVDatlassian/fisheye< 4.8.2
CVEListV5atlassian/crucibleunspecified4.8.2
NVDatlassian/crucible< 4.8.2

🔴Vulnerability Details

2
GHSA
GHSA-qr52-gfv9-hv5x: The review coverage resource in Atlassian Fisheye and Crucible before version 42022-05-24
CVEList
CVE-2020-4023: The review coverage resource in Atlassian Fisheye and Crucible before version 42020-06-01
CVE-2020-4023 (MEDIUM CVSS 5.4) | The review coverage resource in Atl | cvebase.io