Show filters
51 Total Results
Displaying 11-20 of 51
Sort by:
Attacker Value
Unknown
CVE-2020-14191
Disclosure Date: November 19, 2020 (last updated November 28, 2024)
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4.
0
Attacker Value
Unknown
CVE-2020-14192
Disclosure Date: November 11, 2020 (last updated February 22, 2025)
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.
0
Attacker Value
Unknown
CVE-2020-4023
Disclosure Date: May 29, 2020 (last updated February 21, 2025)
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.
0
Attacker Value
Unknown
CVE-2020-4017
Disclosure Date: April 21, 2020 (last updated November 27, 2024)
The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application links via an information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2020-4013
Disclosure Date: April 21, 2020 (last updated February 21, 2025)
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.
0
Attacker Value
Unknown
CVE-2020-4014
Disclosure Date: April 21, 2020 (last updated November 27, 2024)
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
0
Attacker Value
Unknown
CVE-2020-4015
Disclosure Date: April 21, 2020 (last updated November 27, 2024)
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2020-4018
Disclosure Date: April 21, 2020 (last updated February 21, 2025)
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2020-4016
Disclosure Date: April 21, 2020 (last updated November 27, 2024)
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2019-15008
Disclosure Date: December 11, 2019 (last updated November 27, 2024)
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.
0