CVE-2017-18090: XSS
Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18090?
CVE-2017-18090 is a cross-site scripting (XSS) vulnerability in Atlassian Fisheye before version 4.5.1 and before version 4.6.0.
How does CVE-2017-18090 affect Atlassian Fisheye?
CVE-2017-18090 allows remote attackers to inject arbitrary HTML or JavaScript via a cross-site scripting attack on the name of a commit author in Atlassian Fisheye.
What is the severity of CVE-2017-18090?
The severity of CVE-2017-18090 is medium with a CVSS score of 6.1.
How can I fix CVE-2017-18090 in Atlassian Fisheye 4.5.x?
To fix CVE-2017-18090 in Atlassian Fisheye 4.5.x, upgrade to version 4.5.1 which includes the fix.
How can I fix CVE-2017-18090 in Atlassian Fisheye 4.6.0?
To fix CVE-2017-18090 in Atlassian Fisheye 4.6.0, upgrade to a version that includes the fix.