CVE-2018-13392: XSS
Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13392?
CVE-2018-13392 is a vulnerability in Atlassian Fisheye and Crucible before version 4.6.0 that allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers who can inject arbitrary HTML or JavaScript through a cross-site scripting (XSS) attack on linked issue keys in Atlassian Fisheye and Crucible applications.
What is the severity of CVE-2018-13392?
The severity of CVE-2018-13392 is medium with a CVSS score of 6.1.
Which versions of Atlassian Fisheye and Crucible are affected by this vulnerability?
Atlassian Fisheye and Crucible versions up to but excluding 4.6.0 are affected by this vulnerability.
How can I mitigate the CVE-2018-13392 vulnerability?
To mitigate the CVE-2018-13392 vulnerability, users should update their Atlassian Fisheye and Crucible installations to version 4.6.0 or higher.