CVE-2017-9509: XSS
Published Aug 24, 2017
·Updated
The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.
Affected Software
2 affected components
Atlassian Crucible<=4.4.0
Atlassian FishEye<=4.4.0
Event History
Aug 24, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-9509?
CVE-2017-9509 has a severity rating that indicates it poses a significant risk due to its potential for remote code execution through XSS.
2
How do I fix CVE-2017-9509?
To fix CVE-2017-9509, upgrade Atlassian Crucible or FishEye to version 4.4.1 or later.
3
What types of attacks does CVE-2017-9509 enable?
CVE-2017-9509 enables remote attackers to conduct cross site scripting (XSS) attacks.
4
Which versions of Atlassian Crucible are affected by CVE-2017-9509?
CVE-2017-9509 affects Atlassian Crucible versions prior to 4.4.1.
5
Can CVE-2017-9509 affect other Atlassian products?
Yes, CVE-2017-9509 can also affect Atlassian FishEye versions prior to 4.4.1.