Atlassian Fisheye vulnerabilities
53 known vulnerabilities affecting atlassian/fisheye.
Total CVEs
53
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH10MEDIUM38
Vulnerabilities
Page 2 of 3
CVE-2020-4015MEDIUMCVSS 4.3fixed in 4.8.1≥ unspecified, < 4.8.12020-06-01
CVE-2020-4015 [MEDIUM] CVE-2020-4015: The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 all
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
cvelistv5nvd
CVE-2019-15008MEDIUMCVSS 6.1fixed in 4.7.3≥ unspecified, < 4.7.32019-12-11
CVE-2019-15008 [MEDIUM] CWE-79 CVE-2019-15008: The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 al
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.
cvelistv5nvd
CVE-2019-15009MEDIUMCVSS 4.3fixed in 4.8.0≥ unspecified, < 4.8.02019-12-11
CVE-2019-15009 [MEDIUM] CVE-2019-15009: The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.
cvelistv5nvd
CVE-2019-15007MEDIUMCVSS 4.8fixed in 4.7.3≥ unspecified, < 4.7.32019-12-11
CVE-2019-15007 [MEDIUM] CWE-79 CVE-2019-15007: The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers t
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.
cvelistv5nvd
CVE-2019-15005MEDIUMCVSS 4.3fixed in 4.7.2≥ unspecified, < 4.7.22019-11-08
CVE-2019-15005 [MEDIUM] CWE-862 CVE-2019-15005: The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivilege
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulne
cvelistv5nvd
CVE-2018-20239MEDIUMCVSS 5.4fixed in 4.7.02019-04-30
CVE-2018-20239 [MEDIUM] CWE-79 CVE-2018-20239: Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a pl
nvd
CVE-2018-20241MEDIUMCVSS 5.4fixed in 4.7.02019-02-20
CVE-2018-20241 [MEDIUM] CWE-79 CVE-2018-20241: The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.
nvd
CVE-2018-20240MEDIUMCVSS 4.8fixed in 4.7.02019-02-20
CVE-2018-20240 [MEDIUM] CWE-79 CVE-2018-20240: The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allow
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.
nvd
CVE-2018-13399HIGHCVSS 7.8fixed in 4.6.12018-10-16
CVE-2018-13399 [HIGH] CWE-732 CVE-2018-13399: The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
nvd
CVE-2018-13398MEDIUMCVSS 6.5fixed in 4.5.42018-09-18
CVE-2018-13398 [MEDIUM] CWE-352 CVE-2018-13398: The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 all
The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.
nvd
CVE-2018-13392MEDIUMCVSS 6.1fixed in 4.6.02018-08-13
CVE-2018-13392 [MEDIUM] CWE-79 CVE-2018-13392: Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to i
Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.
nvd
CVE-2018-13388MEDIUMCVSS 5.4fixed in 4.5.32018-07-10
CVE-2018-13388 [MEDIUM] CWE-79 CVE-2018-13388: The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote
The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.
nvd
CVE-2017-16859MEDIUMCVSS 6.5fixed in 4.3.2≥ 4.4.0, < 4.4.3+1 more2018-06-28
CVE-2017-16859 [MEDIUM] CWE-22 CVE-2017-16859: The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.
nvd
CVE-2018-5228MEDIUMCVSS 6.1fixed in 4.5.32018-04-24
CVE-2018-5228 [MEDIUM] CWE-79 CVE-2018-5228: The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attac
The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.
nvd
CVE-2018-5223HIGHCVSS 7.2≥ 4.4.0, < 4.4.6≥ 4.5.0, < 4.5.32018-03-29
CVE-2018-5223 [HIGH] CWE-20 CVE-2018-5223: Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained valu
Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repository in Fisheye or Crucible can execute code of their choice on systems that run a vulnerable version of Fisheye or Crucible on the Windows
nvd
CVE-2017-18094MEDIUMCVSS 4.8≥ 4.4.0, < 4.4.3v4.5.02018-03-22
CVE-2017-18094 [MEDIUM] CWE-79 CVE-2017-18094: Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the base path setting of a configured file system repository.
nvd
CVE-2017-18093MEDIUMCVSS 4.8≥ 4.4.0, < 4.4.32018-02-19
CVE-2017-18093 [MEDIUM] CWE-79 CVE-2017-18093: Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the location setting of a configured repository.
nvd
CVE-2017-18090MEDIUMCVSS 6.1v4.5.0vprior to 4.5.1+1 more2018-02-16
CVE-2017-18090 [MEDIUM] CWE-79 CVE-2017-18090: Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before
Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author.
cvelistv5nvd
CVE-2017-18091MEDIUMCVSS 4.8≥ 4.4.0, < 4.4.32018-02-16
CVE-2017-18091 [MEDIUM] CWE-79 CVE-2017-18091: The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed ve
The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the filename of a backup.
nvd
CVE-2017-18035MEDIUMCVSS 4.3fixed in 4.5.12018-02-02
CVE-2017-18035 [MEDIUM] CWE-284 CVE-2017-18035: The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and C
The /rest/review-coverage-chart/1.0/data//.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for it.
nvd