PT-2018-11800 · Atlassian · Crucible+1

Publicado

2018-09-18

·

Atualizado

2018-12-13

·

CVE-2018-13398

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Fisheye and Crucible versions prior to 4.5.4
Description The issue allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability, affecting the administrative smart-commits resource.
Recommendations For versions prior to 4.5.4, update to version 4.5.4 or later to resolve the issue.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-13398

Produtos afetados

Crucible
Fisheye