CVE-2020-4018: CSRF
Published Jun 1, 2020
·Updated
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.
Affected Software
2 affected components
Atlassian Crucible<4.8.1
Atlassian FishEye<4.8.1
Event History
Jun 1, 2020
CVE Published
via MITRE·06:35 AM
Data Sourced
via MITRE·06:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-4018?
CVE-2020-4018 is a vulnerability in Atlassian Fisheye and Crucible that allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.
2
How does CVE-2020-4018 affect Atlassian Crucible?
CVE-2020-4018 affects Atlassian Crucible versions up to and excluding 4.8.1.
3
How does CVE-2020-4018 affect Atlassian FishEye?
CVE-2020-4018 affects Atlassian FishEye versions up to and excluding 4.8.1.
4
What is the severity of CVE-2020-4018?
CVE-2020-4018 has a severity rating of 8.8 (high).
5
How can I fix CVE-2020-4018?
To fix CVE-2020-4018, you should upgrade Atlassian Fisheye and Crucible to version 4.8.1 or later.