Information Disclosure Vulnerability in Atlassian Fisheye Product
CVE-2017-18112
6.5MEDIUM
Summary
A security flaw in Atlassian Fisheye allows remote attackers to expose sensitive HTTP passwords of repositories through the application's logging functionality. This vulnerability specifically affects versions earlier than 4.8.3, enabling unauthorized users to gain access to critical authentication data, posing a significant risk to repository security.
Affected Version(s)
Fisheye < 4.8.3
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved