CVE-2017-14588: XSS
Published Oct 11, 2017
·Updated
Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.
Affected Software
2 affected components
Atlassian Crucible<=4.4.1
Atlassian FishEye<=4.4.1
Event History
Oct 11, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-14588?
CVE-2017-14588 has been classified as a moderate severity vulnerability that allows for cross-site scripting attacks.
2
How do I fix CVE-2017-14588?
To fix CVE-2017-14588, upgrade Atlassian FishEye and Crucible to version 4.4.2 or later.
3
What types of attacks does CVE-2017-14588 enable?
CVE-2017-14588 enables attackers to inject arbitrary HTML or JavaScript through cross-site scripting.
4
Which software versions are affected by CVE-2017-14588?
CVE-2017-14588 affects Atlassian FishEye and Crucible versions prior to 4.4.2.
5
Can CVE-2017-14588 be exploited remotely?
Yes, CVE-2017-14588 can be exploited remotely by attackers.