Insecure Direct Object Reference in Atlassian Fisheye and Crucible
CVE-2020-29446
5.3MEDIUM
What is CVE-2020-29446?
The vulnerability identified in certain versions of Atlassian Fisheye and Crucible consists of an Insecure Direct Object Reference (IDOR) that enables remote attackers to access local files through the WEB-INF directory. This exposure occurs in versions prior to 4.8.5, allowing unauthorized data access that can lead to further security breaches.
Affected Version(s)
Crucible < 4.8.5
Fisheye < 4.8.5