cbcvebase.

Atlassian Fisheye vulnerabilities

53 known vulnerabilities affecting atlassian/fisheye.

Total CVEs
53
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH10MEDIUM38

Vulnerabilities

Page 2 of 3
CVE-2020-4016P4MEDIUMCVSS 5.3fixed in 4.8.1≥ unspecified, < 4.8.12020-06-01
CVE-2020-4016 [MEDIUM] CVE-2020-4016: The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye an The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.
nvd
CVE-2020-4017P4MEDIUMCVSS 5.3fixed in 4.8.1≥ unspecified, < 4.8.12020-06-01
CVE-2020-4017 [MEDIUM] CVE-2020-4017: The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fish The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application links via an information disclosure vulnerability.
nvd
CVE-2018-13392P4MEDIUMCVSS 6.1fixed in 4.6.02018-08-13
CVE-2018-13392 [MEDIUM] CWE-79 CVE-2018-13392: Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to i Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.
nvd
CVE-2017-18034P4MEDIUMCVSS 5.4fixed in 4.5.1v4.6.02018-02-02
CVE-2017-18034 [MEDIUM] CWE-79 CVE-2017-18034: The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows a The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in via a specially crafted repository branch name when trying to display deleted files of the b
nvd
CVE-2018-5228P4MEDIUMCVSS 6.1fixed in 4.5.32018-04-24
CVE-2018-5228 [MEDIUM] CWE-79 CVE-2018-5228: The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attac The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.
nvd
CVE-2021-43956P4MEDIUMCVSS 6.1fixed in 4.8.9≥ unspecified, < 4.8.92022-03-16
CVE-2021-43956 [MEDIUM] CWE-1321 CVE-2021-43956: The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
nvd
CVE-2018-20241P4MEDIUMCVSS 5.4fixed in 4.7.02019-02-20
CVE-2018-20241 [MEDIUM] CWE-79 CVE-2018-20241: The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.
nvd
CVE-2017-9509P4MEDIUMCVSS 5.4≤ 4.4.02017-08-24
CVE-2017-9509 [MEDIUM] CWE-79 CVE-2017-9509: The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers t The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.
nvd
CVE-2019-15005P4MEDIUMCVSS 4.3fixed in 4.7.2≥ unspecified, < 4.7.22019-11-08
CVE-2019-15005 [MEDIUM] CWE-862 CVE-2019-15005: The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivilege The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulne
nvd
CVE-2017-18035P4MEDIUMCVSS 4.3fixed in 4.5.12018-02-02
CVE-2017-18035 [MEDIUM] CWE-284 CVE-2017-18035: The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and C The /rest/review-coverage-chart/1.0/data//.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for it.
nvd
CVE-2020-4026P4MEDIUMCVSS 4.3≥ unspecified, < 4.8.22020-06-03
CVE-2020-4026 [MEDIUM] CWE-863 CVE-2020-4026: The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from ve The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including those that are restricted or otherwise hidden, through an incorrect authorizat
nvd
CVE-2017-18090P4MEDIUMCVSS 6.1v4.5.0vprior to 4.5.1+1 more2018-02-16
CVE-2017-18090 [MEDIUM] CWE-79 CVE-2017-18090: Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author.
nvd
CVE-2019-15008P4MEDIUMCVSS 6.1fixed in 4.7.3≥ unspecified, < 4.7.32019-12-11
CVE-2019-15008 [MEDIUM] CWE-79 CVE-2019-15008: The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 al The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.
nvd
CVE-2018-13388P4MEDIUMCVSS 5.4fixed in 4.5.32018-07-10
CVE-2018-13388 [MEDIUM] CWE-79 CVE-2018-13388: The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.
nvd
CVE-2017-9510P4MEDIUMCVSS 5.4≤ 4.4.02017-08-24
CVE-2017-9510 [MEDIUM] CWE-79 CVE-2017-9510: The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.
nvd
CVE-2020-4023P4MEDIUMCVSS 5.4fixed in 4.8.2≥ unspecified, < 4.8.22020-06-01
CVE-2020-4023 [MEDIUM] CWE-79 CVE-2020-4023: The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote at The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.
nvd
CVE-2020-4013P4MEDIUMCVSS 5.4fixed in 4.8.1≥ unspecified, < 4.8.12020-06-01
CVE-2020-4013 [MEDIUM] CWE-79 CVE-2020-4013: The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers t The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.
nvd
CVE-2021-43954P4MEDIUMCVSS 4.3fixed in 4.8.9≥ unspecified, < 4.8.92022-03-14
CVE-2021-43954 [MEDIUM] CWE-918 CVE-2021-43954: The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
nvd
CVE-2017-14588P4MEDIUMCVSS 6.1≤ 4.4.12017-10-11
CVE-2017-14588 [MEDIUM] CWE-79 CVE-2017-14588: Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to i Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.
nvd
CVE-2017-14587P4MEDIUMCVSS 5.4≤ 4.4.12017-10-11
CVE-2017-14587 [MEDIUM] CWE-79 CVE-2017-14587: The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 all The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.
nvd
Atlassian Fisheye vulnerabilities | cvebase