CVE-2020-14191: High severity atlassian crucible vulnerability
Published Nov 25, 2020
·Updated
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4.
Affected Software
2 affected components
Atlassian Crucible<4.8.4
Atlassian FishEye<4.8.4
Remediation
Patch Available
Patch Available
Event History
Nov 25, 2020
CVE Published
via MITRE·09:55 PM
Data Sourced
via MITRE·09:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-14191?
CVE-2020-14191 is a Denial of Service (DoS) vulnerability in Atlassian Fisheye/Crucible.
2
How does CVE-2020-14191 impact Atlassian Fisheye/Crucible?
CVE-2020-14191 allows remote attackers to impact the availability of Atlassian Fisheye/Crucible.
3
What versions of Atlassian Fisheye/Crucible are affected by CVE-2020-14191?
Versions before 4.8.4 of Atlassian Fisheye/Crucible are affected by CVE-2020-14191.
4
What is the severity of CVE-2020-14191?
CVE-2020-14191 has a severity rating of high (7.5).
5
How can I fix CVE-2020-14191 in Atlassian Fisheye/Crucible?
To fix CVE-2020-14191, update Atlassian Fisheye/Crucible to version 4.8.4 or later.