Information Disclosure Vulnerability in Atlassian Fisheye Product
CVE-2017-18112

6.5MEDIUM

Key Information:

Vendor
Atlassian
Status
Vendor
CVE Published:
5 August 2020

Summary

A security flaw in Atlassian Fisheye allows remote attackers to expose sensitive HTTP passwords of repositories through the application's logging functionality. This vulnerability specifically affects versions earlier than 4.8.3, enabling unauthorized users to gain access to critical authentication data, posing a significant risk to repository security.

Affected Version(s)

Fisheye < 4.8.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.