First published: Mon Jun 01 2020(Updated: )
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Crucible | <4.8.1 | |
Atlassian FishEye | <4.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4015.
The severity of CVE-2020-4015 is medium (score of 4.3).
Altassian Crucible and Atlassian FishEye versions up to 4.8.1 are affected by CVE-2020-4015.
Remote attackers can exploit CVE-2020-4015 to view user email addresses through the /json/fe/activeUserFinder.do resource.
Yes, you can find reference links for CVE-2020-4015 here: [link-1] [link-2].