CVE-2017-18035: Medium severity Atlassian FishEye vulnerability
The /rest/review-coverage-chart/1.0/data/<repositoryname>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for it.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18035?
CVE-2017-18035 is a vulnerability in Atlassian Fisheye and Crucible that allows remote attackers to determine the existence of a repository and access review coverage.
What is the severity of CVE-2017-18035?
CVE-2017-18035 has a severity rating of 4.3, which is considered medium.
How does CVE-2017-18035 affect Atlassian FishEye?
CVE-2017-18035 affects Atlassian FishEye versions up to exclusive 4.5.1.
How does CVE-2017-18035 affect Atlassian Crucible?
CVE-2017-18035 affects Atlassian Crucible versions up to exclusive 4.5.1.
Are there any fixes or patches available for CVE-2017-18035?
To fix CVE-2017-18035, it is recommended to upgrade Atlassian Fisheye and Crucible to version 4.5.1 or higher.