First published: Wed Nov 25 2020(Updated: )
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Crucible | <4.8.4 | |
Atlassian FishEye | <4.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14191 is a Denial of Service (DoS) vulnerability in Atlassian Fisheye/Crucible.
CVE-2020-14191 allows remote attackers to impact the availability of Atlassian Fisheye/Crucible.
Versions before 4.8.4 of Atlassian Fisheye/Crucible are affected by CVE-2020-14191.
CVE-2020-14191 has a severity rating of high (7.5).
To fix CVE-2020-14191, update Atlassian Fisheye/Crucible to version 4.8.4 or later.