CVE-2020-4014: Medium severity Atlassian Crucible vulnerability
Published Jun 1, 2020
·Updated
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
Affected Software
2 affected components
Atlassian Crucible<4.8.1
Atlassian FishEye<4.8.1
Event History
Jun 1, 2020
CVE Published
via MITRE·06:35 AM
Data Sourced
via MITRE·06:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2020-4014.
2
What is the affected software?
The affected software is Atlassian Crucible and Atlassian FishEye versions up to 4.8.1.
3
What is the severity of CVE-2020-4014?
The severity of CVE-2020-4014 is medium with a CVSS score of 4.3.
4
How does CVE-2020-4014 work?
CVE-2020-4014 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
5
Is there a fix available for CVE-2020-4014?
Yes, the fix for CVE-2020-4014 is available in Atlassian Fisheye and Crucible version 4.8.1.