CVE-2017-9511: Path Traversal
The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9511?
CVE-2017-9511 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2017-9511?
To mitigate CVE-2017-9511, upgrade Atlassian Fisheye and Crucible to version 4.4.1 or later.
What types of attacks does CVE-2017-9511 enable?
CVE-2017-9511 allows anonymous remote attackers to perform path traversal attacks which can lead to unauthorized file access.
Which versions of Atlassian software are affected by CVE-2017-9511?
CVE-2017-9511 affects versions of Atlassian Fisheye and Crucible up to 4.4.0.
Is Microsoft Windows necessary for the CVE-2017-9511 vulnerability to be exploited?
Yes, CVE-2017-9511 requires the vulnerable version of Atlassian software to be running on a Microsoft Windows operating system.