PT-2022-11955 · Atlassian · Fisheye/Crucible

Published

2022-03-16

·

Updated

2024-10-07

·

CVE-2021-43957

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Fisheye & Crucible versions prior to 4.8.9
Description The issue allows remote attackers to browse local files due to an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. This is possible because of a lack of URL decoding, which bypasses a previous fix.
Recommendations For versions prior to 4.8.9, update to version 4.8.9 or later to resolve the issue.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43957

Affected Products

Fisheye/Crucible