First published: Tue Apr 21 2020(Updated: )
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Crucible | <4.8.1 | |
Atlassian FishEye | <4.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2020-4014.
The affected software is Atlassian Crucible and Atlassian FishEye versions up to 4.8.1.
The severity of CVE-2020-4014 is medium with a CVSS score of 4.3.
CVE-2020-4014 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
Yes, the fix for CVE-2020-4014 is available in Atlassian Fisheye and Crucible version 4.8.1.