First published: Mon Jan 18 2021(Updated: )
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Crucible | <4.8.5 | |
Atlassian FishEye | <4.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-29446.
The severity of CVE-2020-29446 is medium with a severity score of 5.3.
Versions before 4.8.5 of Atlassian Fisheye and Crucible are affected.
An attacker can exploit this vulnerability by browsing local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory.
Yes, updating to version 4.8.5 or later of Atlassian Fisheye and Crucible will fix the vulnerability.