PT-2018-2132 · Atlassian+1 · Crucible+2

Published

2018-09-28

·

Updated

2019-10-03

·

CVE-2018-13399

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlassian Fisheye and Crucible versions prior to 4.6.1 Microsoft Windows Installer for Atlassian Fisheye and Crucible versions prior to 4.6.1
Description The issue is related to permission handling errors in the code search and comparison tool Fisheye and the code review tool Crucible. Exploitation of this issue may allow an attacker to escalate their privileges. The Microsoft Windows Installer for these tools has weak permissions on the installation directory, which can be exploited by local attackers to gain elevated privileges.
Recommendations For Atlassian Fisheye and Crucible versions prior to 4.6.1, update to version 4.6.1 or later to resolve the issue. For Microsoft Windows Installer for Atlassian Fisheye and Crucible versions prior to 4.6.1, update to version 4.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the installation directory to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00084
CVE-2018-13399

Affected Products

Fisheye
Crucible
Windows Installer