CVE-2020-14190: High severity atlassian crucible vulnerability
Published Nov 25, 2020
·Updated
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.
Affected Software
2 affected components
Atlassian Crucible<4.8.4
Atlassian FishEye<4.8.4
Remediation
Patch Available
Patch Available
Event History
Nov 25, 2020
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2020-14190.
2
What is the severity level of CVE-2020-14190?
The severity level of CVE-2020-14190 is high with a value of 7.5.
3
Which versions of Atlassian Fisheye/Crucible are affected?
The affected versions of Atlassian Fisheye/Crucible are before version 4.8.4.
4
How can remote attackers exploit this vulnerability?
Remote attackers can achieve Regex Denial of Service via user-supplied regex in EyeQL.
5
Are there any references for this vulnerability?
Yes, you can find references for this vulnerability at the following URLs: [https://jira.atlassian.com/browse/CRUC-8498](https://jira.atlassian.com/browse/CRUC-8498) and [https://jira.atlassian.com/browse/FE-7336](https://jira.atlassian.com/browse/FE-7336).