PT-2020-17165 · Atlassian · Crucible
Published
2020-12-21
·
Updated
2020-12-22
·
CVE-2020-29447
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Atlassian Crucible versions prior to 4.7.4
Atlassian Crucible versions 4.8.0 through 4.8.4
Description
The issue allows remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews.
Recommendations
For versions prior to 4.7.4, update to version 4.7.4 or later.
For versions 4.8.0 through 4.8.4, update to version 4.8.5 or later.
As a temporary workaround, consider restricting access to the file upload request feature in code reviews until a patch is available.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crucible