CVE-2017-18094: XSS
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the base path setting of a configured file system repository.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18094?
CVE-2017-18094 is a vulnerability in Atlassian Fisheye and Crucible that allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
What is the severity of CVE-2017-18094?
The severity of CVE-2017-18094 is medium with a CVSS score of 4.8.
Which versions of Atlassian FishEye are affected by CVE-2017-18094?
Atlassian FishEye versions 4.4.0 to 4.4.3 are affected by CVE-2017-18094.
Which versions of Atlassian Crucible are affected by CVE-2017-18094?
Atlassian Crucible versions 4.4.0 to 4.4.3 are affected by CVE-2017-18094.
How can I fix CVE-2017-18094?
To fix CVE-2017-18094, upgrade to Atlassian FishEye and Crucible version 4.4.3 (the fixed version for 4.4.x) or version 4.5.0.