CVE-2020-4015: Medium severity atlassian crucible vulnerability
Published Jun 1, 2020
·Updated
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
Affected Software
2 affected components
Atlassian Crucible<4.8.1
Atlassian FishEye<4.8.1
Event History
Jun 1, 2020
CVE Published
via MITRE·06:35 AM
Data Sourced
via MITRE·06:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-4015.
2
What is the severity of CVE-2020-4015?
The severity of CVE-2020-4015 is medium (score of 4.3).
3
What software versions are affected by CVE-2020-4015?
Altassian Crucible and Atlassian FishEye versions up to 4.8.1 are affected by CVE-2020-4015.
4
How can remote attackers exploit CVE-2020-4015?
Remote attackers can exploit CVE-2020-4015 to view user email addresses through the /json/fe/activeUserFinder.do resource.
5
Is there a reference link for CVE-2020-4015?
Yes, you can find reference links for CVE-2020-4015 here: [link-1] [link-2].