PT-2020-17165 · Atlassian · Crucible

Published

2020-12-21

·

Updated

2020-12-22

·

CVE-2020-29447

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Atlassian Crucible versions prior to 4.7.4 Atlassian Crucible versions 4.8.0 through 4.8.4
Description The issue allows remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews.
Recommendations For versions prior to 4.7.4, update to version 4.7.4 or later. For versions 4.8.0 through 4.8.4, update to version 4.8.5 or later. As a temporary workaround, consider restricting access to the file upload request feature in code reviews until a patch is available.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29447

Affected Products

Crucible