CVE-2018-13398: CSRF
Published Sep 18, 2018
·Updated
The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.
Affected Software
2 affected components
Atlassian Crucible<4.5.4
Atlassian FishEye<4.5.4
Event History
Sep 18, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-13398.
2
What is the affected software?
The affected software includes Atlassian Crucible and Atlassian FishEye versions up to 4.5.4.
3
What is the severity of CVE-2018-13398?
The severity of CVE-2018-13398 is medium (CVSS score 6.5).
4
How does CVE-2018-13398 allow remote attackers to modify smart-commit settings?
CVE-2018-13398 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.
5
Is there a fix available for CVE-2018-13398?
Yes, the fix for CVE-2018-13398 is available in version 4.5.4 of Atlassian Crucible and Atlassian FishEye.