Atlassian · Fisheye/Crucible · CVE-2018-20240
Name of the Vulnerable Software and Affected Versions:
Atlassian Fisheye and Crucible versions prior to 4.7.0
Description:
The issue allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the `href` parameter. This can be exploited by attackers to execute malicious scripts on the affected system.
Recommendations:
For versions prior to 4.7.0, update to version 4.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the administrative linker functionality to minimize the risk of exploitation. Avoid using the `href` parameter in the affected functionality until the issue is resolved.