CVE-2019-15008: XSS
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15008?
CVE-2019-15008 refers to a cross site scripting (XSS) vulnerability in Atlassian Fisheye and Crucible versions before 4.7.3.
How does the /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible allow attackers to inject arbitrary HTML or JavaScript?
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows attackers to inject arbitrary HTML or JavaScript through a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.
What is the severity of CVE-2019-15008?
CVE-2019-15008 has a severity rating of 6.1 (Medium).
Which software versions are affected by CVE-2019-15008?
Atlassian Fisheye and Crucible versions before 4.7.3 are affected by CVE-2019-15008.
How can I fix the vulnerability CVE-2019-15008?
To fix the vulnerability, update Atlassian Fisheye and Crucible to version 4.7.3 or later.