First published: Mon Feb 01 2021(Updated: )
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Crucible | <4.8.4 | |
Atlassian FishEye | <4.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14192 is an Information Disclosure vulnerability in Atlassian Fisheye and Crucible.
The severity of CVE-2020-14192 is medium, with a severity score of 4.3.
CVE-2020-14192 allows remote attackers to view a product's SEN (Support Entitlement Number) by exploiting the information disclosure vulnerability in the x-asen response header from Atlassian Analytics.
The affected versions of Atlassian Fisheye and Crucible are versions before 4.8.4.
To fix CVE-2020-14192, upgrade your Atlassian Fisheye and Crucible installations to version 4.8.4 or later.