CVE-2021-43956: XSS
Published Mar 16, 2022
·Updated
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
Affected Software
2 affected components
Atlassian Crucible<4.8.9
Atlassian FishEye<4.8.9
Event History
Mar 16, 2022
CVE Published
via MITRE·12:55 AM
Data Sourced
via MITRE·12:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-43956.
2
What software products are affected by this vulnerability?
The Atlassian Crucible and Atlassian FishEye software versions up to 4.8.9 are affected by this vulnerability.
3
What is the severity of CVE-2021-43956?
The severity of CVE-2021-43956 is medium.
4
How does CVE-2021-43956 allow remote attackers to inject arbitrary HTML and/or JavaScript?
CVE-2021-43956 allows remote attackers to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability in the jQuery deserialize library.
5
How can I fix CVE-2021-43956?
To fix CVE-2021-43956, it is recommended to update Fisheye and Crucible to version 4.8.9 or later.