Cross-Site Request Forgery in Atlassian Fisheye and Crucible Setup Process
CVE-2020-4018
8.8HIGH
What is CVE-2020-4018?
The setup resources in Atlassian Fisheye and Crucible prior to version 4.8.1 contain a cross-site request forgery (CSRF) vulnerability that allows unauthorized remote attackers to manipulate the setup process. This security flaw can potentially lead to an unauthorized completion of the setup, affecting the integrity and security of the applications.
Affected Version(s)
Crucible < 4.8.1
Fisheye < 4.8.1