PT-2018-2132 · Atlassian+1 · Crucible+2
Published
2018-09-28
·
Updated
2019-10-03
·
CVE-2018-13399
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Atlassian Fisheye and Crucible versions prior to 4.6.1
Microsoft Windows Installer for Atlassian Fisheye and Crucible versions prior to 4.6.1
Description
The issue is related to permission handling errors in the code search and comparison tool Fisheye and the code review tool Crucible. Exploitation of this issue may allow an attacker to escalate their privileges. The Microsoft Windows Installer for these tools has weak permissions on the installation directory, which can be exploited by local attackers to gain elevated privileges.
Recommendations
For Atlassian Fisheye and Crucible versions prior to 4.6.1, update to version 4.6.1 or later to resolve the issue.
For Microsoft Windows Installer for Atlassian Fisheye and Crucible versions prior to 4.6.1, update to version 4.6.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the installation directory to minimize the risk of exploitation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fisheye
Crucible
Windows Installer