Regex Denial of Service Vulnerability in Atlassian Fisheye/Crucible
CVE-2020-14190
7.5HIGH
What is CVE-2020-14190?
Atlassian Fisheye/Crucible versions prior to 4.8.4 are susceptible to a Regex Denial of Service vulnerability, which can be exploited by remote attackers through the manipulation of user-supplied regular expressions in EyeQL. This flaw can lead to severe disruption of service, impacting availability and performance.
Affected Version(s)
Crucible < 4.8.4
Fisheye < 4.8.4