CVE-2020-29446: Medium severity atlassian crucible vulnerability
Published Jan 18, 2021
·Updated
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.
Affected Software
2 affected components
Atlassian Crucible<4.8.5
Atlassian FishEye<4.8.5
Event History
Jan 18, 2021
CVE Published
via MITRE·01:30 AM
Data Sourced
via MITRE·01:30 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-29446.
2
What is the severity of CVE-2020-29446?
The severity of CVE-2020-29446 is medium with a severity score of 5.3.
3
Which versions of Atlassian Fisheye and Crucible are affected?
Versions before 4.8.5 of Atlassian Fisheye and Crucible are affected.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by browsing local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory.
5
Is there a fix available for this vulnerability?
Yes, updating to version 4.8.5 or later of Atlassian Fisheye and Crucible will fix the vulnerability.