Information Disclosure Vulnerability in Atlassian Fisheye and Crucible
CVE-2020-4015
4.3MEDIUM
What is CVE-2020-4015?
An information disclosure vulnerability exists in Atlassian Fisheye and Crucible versions prior to 4.8.1. This vulnerability allows remote attackers to gain unauthorized access to user email addresses by exploiting the /json/fe/activeUserFinder.do resource. Attackers can misuse this information to target users for phishing attacks or other malicious activities, emphasizing the importance of timely updates to secure sensitive user data.
Affected Version(s)
Crucible < 4.8.1
Fisheye < 4.8.1