Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Adam Slaski

#51668of 53,612
4.3Total CVSS
Vulnerabilities · 1
PT-2018-6627
4.3
2018-02-02
Atlassian · Fisheye/Crucible · CVE-2017-18035
Name of the Vulnerable Software and Affected Versions: Atlassian Fisheye and Crucible versions prior to 4.5.1 and 4.6.0 Description: The issue concerns a missing permissions check in the /rest/review-coverage-chart/1.0/data/<repository name>/.json resource. This allows remote attackers without access to a particular repository to determine its existence and access review coverage statistics. Recommendations: For versions prior to 4.5.1, update to version 4.5.1 or later. For versions prior to 4.6.0, update to version 4.6.0 or later.