Information Disclosure Vulnerability in Fisheye and Crucible by Atlassian
CVE-2021-43955
4.3MEDIUM
Summary
The vulnerability in Fisheye and Crucible allows authenticated remote attackers to access sensitive information about installation directories through the /rest-service-fecru/server-v1 resource. This flaw exists in versions before 4.8.9, posing risks to users by potentially revealing details that could be exploited for further attacks.
Affected Version(s)
Crucible < 4.8.9
Fisheye < 4.8.9
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved