First published: Wed Mar 16 2022(Updated: )
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.
Credit: security@atlassian.com security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Crucible | <4.8.9 | |
Atlassian FishEye | <4.8.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43955 is a vulnerability in Fisheye and Crucible before version 4.8.9 that allows authenticated remote attackers to obtain information about installation directories.
CVE-2021-43955 affects Atlassian Crucible and FishEye versions prior to 4.8.9, allowing authenticated remote attackers to obtain installation directory information.
CVE-2021-43955 has a severity rating of 4.3 (medium).
To fix CVE-2021-43955, update Fisheye and Crucible to version 4.8.9 or newer.
You can find more information about CVE-2021-43955 at the following references: [CRUC-8533](https://jira.atlassian.com/browse/CRUC-8533) and [FE-7397](https://jira.atlassian.com/browse/FE-7397).