Atlassian Fisheye vulnerabilities
53 known vulnerabilities affecting atlassian/fisheye.
Total CVEs
53
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH10MEDIUM38
Vulnerabilities
Page 3 of 3
CVE-2017-9508P4MEDIUMCVSS 5.4v4.3.1v4.4.02017-08-24
CVE-2017-9508 [MEDIUM] CWE-79 CVE-2017-9508: Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to i
Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.
nvd
CVE-2020-4014P4MEDIUMCVSS 4.3fixed in 4.8.1≥ unspecified, < 4.8.12020-06-01
CVE-2020-4014 [MEDIUM] CVE-2020-4014: The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows r
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
nvd
CVE-2019-15009P4MEDIUMCVSS 4.3fixed in 4.8.0≥ unspecified, < 4.8.02019-12-11
CVE-2019-15009 [MEDIUM] CVE-2019-15009: The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.
nvd
CVE-2017-9507P4MEDIUMCVSS 5.4≤ 4.4.02017-08-24
CVE-2017-9507 [MEDIUM] CWE-79 CVE-2017-9507: The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows r
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.
nvd
CVE-2020-4015P4MEDIUMCVSS 4.3fixed in 4.8.1≥ unspecified, < 4.8.12020-06-01
CVE-2020-4015 [MEDIUM] CVE-2020-4015: The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 all
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
nvd
CVE-2020-14192P4MEDIUMCVSS 4.3fixed in 4.8.4≥ unspecified, < 4.8.42021-02-02
CVE-2020-14192 [MEDIUM] CWE-200 CVE-2020-14192: Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN v
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.
nvd
CVE-2021-43955P4MEDIUMCVSS 4.3fixed in 4.8.9≥ unspecified, < 4.8.92022-03-16
CVE-2021-43955 [MEDIUM] CVE-2021-43955: The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed auth
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.
nvd
CVE-2018-20240P4MEDIUMCVSS 4.8fixed in 4.7.02019-02-20
CVE-2018-20240 [MEDIUM] CWE-79 CVE-2018-20240: The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allow
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.
nvd
CVE-2017-18093P4MEDIUMCVSS 4.8≥ 4.4.0, < 4.4.32018-02-19
CVE-2017-18093 [MEDIUM] CWE-79 CVE-2017-18093: Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the location setting of a configured repository.
nvd
CVE-2017-18091P4MEDIUMCVSS 4.8≥ 4.4.0, < 4.4.32018-02-16
CVE-2017-18091 [MEDIUM] CWE-79 CVE-2017-18091: The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed ve
The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the filename of a backup.
nvd
CVE-2017-18094P4MEDIUMCVSS 4.8≥ 4.4.0, < 4.4.3v4.5.02018-03-22
CVE-2017-18094 [MEDIUM] CWE-79 CVE-2017-18094: Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the base path setting of a configured file system repository.
nvd
CVE-2019-15007P4MEDIUMCVSS 4.8fixed in 4.7.3≥ unspecified, < 4.7.32019-12-11
CVE-2019-15007 [MEDIUM] CWE-79 CVE-2019-15007: The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers t
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.
nvd
CVE-2011-4822P4MEDIUMCVSS 4.3v1.3v1.4+51 more2011-12-15
CVE-2011-4822 [MEDIUM] CWE-79 CVE-2011-4822: Multiple cross-site scripting (XSS) vulnerabilities in the user profile feature in Atlassian FishEye
Multiple cross-site scripting (XSS) vulnerabilities in the user profile feature in Atlassian FishEye before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) snippets in a user comment, which is not properly handled in a Confluence page, or (2) the user profile display name, which is not properly handled in a FishEye page.
nvd
← Previous3 / 3