PT-2020-6902 · Atlassian · Fisheye/Crucible

Robin Sim

·

Published

2020-11-25

·

Updated

2021-07-21

·

CVE-2020-14190

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Atlassian Fisheye/Crucible versions prior to 4.8.4
Description The issue is related to a Regex Denial of Service in EyeQL, where remote attackers can achieve this via user-supplied regex. This can lead to an uncontrolled consumption of resources, potentially allowing a remote attacker to cause a denial of service.
Recommendations For versions prior to 4.8.4, update to version 4.8.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of EyeQL to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05472
CVE-2020-14190

Affected Products

Fisheye/Crucible