CVE-2017-18112: Infoleak
Published Aug 5, 2020
·Updated
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.
Affected Software
1 affected component
Atlassian FishEye<4.8.3
Event History
Aug 5, 2020
CVE Published
via MITRE·03:25 AM
Data Sourced
via MITRE·03:25 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-18112.
2
Which software is affected by CVE-2017-18112?
Affected versions of Atlassian FishEye are impacted by this vulnerability.
3
What is the severity of CVE-2017-18112?
The severity of CVE-2017-18112 is considered medium with a severity value of 6.5.
4
How can remote attackers exploit CVE-2017-18112?
Remote attackers can exploit CVE-2017-18112 to view the HTTP password of a repository through an Information Disclosure vulnerability in the logging feature.
5
How can I fix CVE-2017-18112?
To fix CVE-2017-18112, upgrade Atlassian FishEye to version 4.8.3 or newer.