Prototype Pollution Vulnerability in Fisheye and Crucible by Atlassian
CVE-2021-43956
6.1MEDIUM
What is CVE-2021-43956?
The jQuery deserialize library found in Fisheye and Crucible before version 4.8.9 is susceptible to a prototype pollution vulnerability. This allows remote attackers to exploit the system by injecting arbitrary HTML and JavaScript. Such exploits can lead to unauthorized actions on behalf of users, potentially compromising the integrity and security of the affected applications. To mitigate this risk, users should update to the latest version of Fisheye and Crucible as recommended by Atlassian.
Affected Version(s)
Crucible < 4.8.9
Fisheye < 4.8.9