Atlassian Fisheye vulnerabilities
53 known vulnerabilities affecting atlassian/fisheye.
Total CVEs
53
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH10MEDIUM38
Vulnerabilities
Page 1 of 3
CVE-2024-21683P1HIGHCVSS 8.8ExploitedPoC≥ 4.8.0, < 4.8.152024-05-21
CVE-2024-21683 [HIGH] CWE-94 CVE-2024-21683: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Conflu
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availabi
nvd
CVE-2012-2926P2CRITICALCVSS 9.1PoCfixed in 2.5.8≥ 2.6, < 2.6.8+1 more2012-05-22
CVE-2012-2926 [CRITICAL] CVE-2012-2926: Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; Fish
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of
nvd
CVE-2022-26136P2CRITICALCVSS 9.8fixed in 4.8.10≥ unspecified, < 4.8.102022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
nvd
CVE-2021-43958P2CRITICALCVSS 9.8fixed in 4.8.9≥ unspecified, < 4.8.92022-03-16
CVE-2021-43958 [CRITICAL] CWE-307 CVE-2021-43958: Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brut
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via a improper restriction of exc
nvd
CVE-2017-16861P3CRITICALCVSS 9.8fixed in 4.4.5≥ 4.5.0, < 4.5.22018-02-01
CVE-2017-16861 [CRITICAL] CVE-2017-16861: It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor
It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. An attacker who can access the web interface of Fisheye or Crucible or who hosts a website that a user who can access the web interface of Fisheye or Crucible visits, is able to exploit this vulnerability to execute Java code of t
nvd
CVE-2017-14591P3CRITICALCVSS 9.0fixed in 4.4.3v4.5.02017-11-29
CVE-2017-14591 [CRITICAL] CWE-88 CVE-2017-14591: Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
nvd
CVE-2022-26137P3HIGHCVSS 8.8fixed in 4.8.10≥ unspecified, < 4.8.102022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
nvd
CVE-2018-5223P3HIGHCVSS 7.2≥ 4.4.0, < 4.4.6≥ 4.5.0, < 4.5.32018-03-29
CVE-2018-5223 [HIGH] CWE-20 CVE-2018-5223: Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained valu
Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repository in Fisheye or Crucible can execute code of their choice on systems that run a vulnerable version of Fisheye or Crucible on the Windows
nvd
CVE-2017-9511P3HIGHCVSS 7.5≤ 4.4.02017-08-24
CVE-2017-9511 [HIGH] CWE-22 CVE-2017-9511: The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous
The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system.
nvd
CVE-2021-43957P3HIGHCVSS 7.5fixed in 4.8.92022-03-16
CVE-2021-43957 [HIGH] CVE-2021-43957: Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.
nvd
CVE-2017-9512P3HIGHCVSS 7.5≤ 4.4.02017-08-24
CVE-2017-9512 [HIGH] CWE-200 CVE-2017-9512: The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.
nvd
CVE-2020-14190P3HIGHCVSS 7.5fixed in 4.8.4≥ unspecified, < 4.8.42020-11-25
CVE-2020-14190 [HIGH] CWE-400 CVE-2020-14190: Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Se
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.
nvd
CVE-2020-14191P3HIGHCVSS 7.5fixed in 4.8.4≥ unspecified, < 4.8.42020-11-25
CVE-2020-14191 [HIGH] CVE-2020-14191: Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's a
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4.
nvd
CVE-2017-16859P3MEDIUMCVSS 6.5fixed in 4.3.2≥ 4.4.0, < 4.4.3+1 more2018-06-28
CVE-2017-16859 [MEDIUM] CWE-22 CVE-2017-16859: The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.
nvd
CVE-2020-4018P3HIGHCVSS 8.8fixed in 4.8.1≥ unspecified, < 4.8.12020-06-01
CVE-2020-4018 [HIGH] CWE-352 CVE-2020-4018: The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers t
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2018-13399P3HIGHCVSS 7.8fixed in 4.6.12018-10-16
CVE-2018-13399 [HIGH] CWE-732 CVE-2018-13399: The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
nvd
CVE-2017-18112P4MEDIUMCVSS 6.5fixed in 4.8.3≥ unspecified, < 4.8.32020-08-05
CVE-2017-18112 [MEDIUM] CWE-200 CVE-2017-18112: Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a reposit
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.
nvd
CVE-2018-20239P4MEDIUMCVSS 5.4fixed in 4.7.02019-04-30
CVE-2018-20239 [MEDIUM] CWE-79 CVE-2018-20239: Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a pl
nvd
CVE-2020-29446P4MEDIUMCVSS 5.3fixed in 4.8.5≥ unspecified, < 4.8.92021-01-18
CVE-2020-29446 [MEDIUM] CWE-639 CVE-2020-29446: Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via a
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.
nvd
CVE-2018-13398P4MEDIUMCVSS 6.5fixed in 4.5.42018-09-18
CVE-2018-13398 [MEDIUM] CWE-352 CVE-2018-13398: The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 all
The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.
nvd
1 / 3Next →