CVE-2017-18093: XSS
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the location setting of a configured repository.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18093?
CVE-2017-18093 is a vulnerability in Atlassian Fisheye and Crucible where remote attackers with permission to add or modify a repository can inject arbitrary HTML or JavaScript, resulting in a cross-site scripting (XSS) attack.
How does CVE-2017-18093 affect Atlassian FishEye and Crucible?
CVE-2017-18093 affects Atlassian FishEye and Crucible versions before 4.4.3 (the fixed version for 4.4.x) and before 4.5.0.
What is the severity of CVE-2017-18093?
The severity of CVE-2017-18093 is medium with a CVSS score of 4.8.
How can remote attackers exploit CVE-2017-18093?
Remote attackers can exploit CVE-2017-18093 by injecting arbitrary HTML or JavaScript through the location parameter, leading to a cross-site scripting (XSS) vulnerability.
How can I fix CVE-2017-18093?
To fix CVE-2017-18093, upgrade Atlassian FishEye and Crucible to version 4.4.3 or later (for 4.4.x) or version 4.5.0 or later.