CVE-2017-9508: XSS
Published Aug 24, 2017
·Updated
Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.
Affected Software
4 affected components
Atlassian Crucible=4.3.1
Atlassian Crucible=4.4.0
Atlassian FishEye=4.3.1
Atlassian FishEye=4.4.0
Event History
Aug 24, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-9508?
CVE-2017-9508 is considered a medium severity vulnerability due to its potential for cross site scripting attacks.
2
How do I fix CVE-2017-9508?
To fix CVE-2017-9508, you should upgrade Atlassian Fisheye or Crucible to version 4.4.1 or later.
3
What are the affected versions in CVE-2017-9508?
CVE-2017-9508 affects Atlassian Fisheye versions 4.3.1 and 4.4.0, as well as Crucible versions 4.3.1 and 4.4.0.
4
What type of vulnerability is CVE-2017-9508?
CVE-2017-9508 is a cross site scripting (XSS) vulnerability allowing remote attackers to inject arbitrary HTML or JavaScript.
5
What products are impacted by CVE-2017-9508?
CVE-2017-9508 impacts Atlassian Fisheye and Crucible.