First published: Mon Dec 21 2020(Updated: )
Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews. The affected versions are before version 4.7.4, and from version 4.8.0 before 4.8.5.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Crucible | <4.7.4 | |
Atlassian Crucible | >=4.8.0<4.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Atlassian Crucible vulnerability is CVE-2020-29447.
The severity of CVE-2020-29447 is medium, with a severity value of 4.3.
CVE-2020-29447 allows remote attackers to impact the availability of Atlassian Crucible through a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews.
The affected versions of Atlassian Crucible are before version 4.7.4 and from version 4.8.0 before 4.8.5.
To fix the CVE-2020-29447 vulnerability, update Atlassian Crucible to version 4.7.4 or 4.8.5.