CVE-2020-4013: XSS
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4013?
CVE-2020-4013 is a vulnerability in Atlassian Fisheye and Crucible that allows remote attackers to inject arbitrary HTML or Javascript through a cross-site scripting (XSS) vulnerability.
How does CVE-2020-4013 impact Atlassian Crucible?
CVE-2020-4013 affects Atlassian Crucible versions up to 4.8.1 and allows remote attackers to inject arbitrary HTML or Javascript via a cross-site scripting (XSS) vulnerability.
How does CVE-2020-4013 impact Atlassian FishEye?
CVE-2020-4013 affects Atlassian FishEye versions up to 4.8.1 and allows remote attackers to inject arbitrary HTML or Javascript via a cross-site scripting (XSS) vulnerability.
What is the severity of CVE-2020-4013?
The severity of CVE-2020-4013 is medium, with a severity value of 5.4.
How can I fix CVE-2020-4013?
To fix CVE-2020-4013, it is recommended to upgrade Atlassian Fisheye and Crucible to version 4.8.1 or later.