Show filters
144 Total Results
Displaying 31-40 of 144
Sort by:
Attacker Value
Unknown
CVE-2020-14190
Disclosure Date: November 19, 2020 (last updated February 22, 2025)
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.
0
Attacker Value
Unknown
CVE-2020-14191
Disclosure Date: November 19, 2020 (last updated November 28, 2024)
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4.
0
Attacker Value
Unknown
CVE-2020-14192
Disclosure Date: November 11, 2020 (last updated February 22, 2025)
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.
0
Attacker Value
Unknown
CVE-2020-22481
Disclosure Date: September 30, 2020 (last updated February 22, 2025)
An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered when the administrator views the information.
0
Attacker Value
Unknown
CVE-2017-18112
Disclosure Date: August 03, 2020 (last updated February 21, 2025)
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.
0
Attacker Value
Unknown
CVE-2020-4023
Disclosure Date: May 29, 2020 (last updated February 21, 2025)
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.
0
Attacker Value
Unknown
CVE-2020-4017
Disclosure Date: April 21, 2020 (last updated November 27, 2024)
The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application links via an information disclosure vulnerability.
0
Attacker Value
Unknown
CVE-2020-4013
Disclosure Date: April 21, 2020 (last updated February 21, 2025)
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.
0
Attacker Value
Unknown
CVE-2020-4014
Disclosure Date: April 21, 2020 (last updated November 27, 2024)
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
0
Attacker Value
Unknown
CVE-2020-4015
Disclosure Date: April 21, 2020 (last updated November 27, 2024)
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
0