Skip to main content

Vendor/product archive

atlassian / crucible CVEs

Beta · best-effort

52 CVEs tagged to atlassian / crucible5 Critical, 10 High, 37 Medium, 0 Low, 0 Unrated.

CVE-2022-26137

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2022-26136

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2021-43958

Published Mar 16, 2022

Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were be…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43957

Published Mar 16, 2022

Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF direc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43956

Published Mar 16, 2022

The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulner…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43955

Published Mar 16, 2022

The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43954

Published Mar 14, 2022

The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14192

Published Feb 2, 2021

Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from A…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29446

Published Jan 18, 2021

Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29447

Published Dec 21, 2020

Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14190

Published Nov 25, 2020

Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before versio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14191

Published Nov 25, 2020

Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleRes…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4023

Published Jun 1, 2020

The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS)…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4018

Published Jun 1, 2020

The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerabil…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4017

Published Jun 1, 2020

The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get informatio…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4016

Published Jun 1, 2020

The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of config…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4015

Published Jun 1, 2020

The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4014

Published Jun 1, 2020

The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4013

Published Jun 1, 2020

The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerab…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15009

Published Dec 11, 2019

The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a projec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15008

Published Dec 11, 2019

The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site s…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15007

Published Dec 11, 2019

The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerab…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 52 CVEsPage 1 of 3