CVE-2021-43957: High severity atlassian crucible vulnerability
Published Mar 16, 2022
·Updated
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.
Affected Software
2 affected components
Atlassian Crucible<4.8.9
Atlassian FishEye<4.8.9
Event History
Mar 16, 2022
CVE Published
via MITRE·12:55 AM
Data Sourced
via MITRE·12:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43957.
2
What is the severity of CVE-2021-43957?
The severity of CVE-2021-43957 is high with a severity value of 7.5.
3
What software versions are affected by CVE-2021-43957?
The affected software versions are Atlassian Fisheye and Crucible before version 4.8.9.
4
How can remote attackers exploit CVE-2021-43957?
Remote attackers can exploit CVE-2021-43957 to browse local files through an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory.
5
Is there a fix for CVE-2021-43957?
Yes, the fix for CVE-2021-43957 is available in version 4.8.9 of Atlassian Fisheye and Crucible.