Insecure Direct Object Reference in Atlassian Fisheye & Crucible
CVE-2021-43957
7.5HIGH
What is CVE-2021-43957?
Certain versions of Atlassian Fisheye & Crucible are susceptible to an Insecure Direct Object Reference vulnerability that allows remote attackers to gain unauthorized access to sensitive local files. This flaw emerges from a lack of URL decoding in the WEB-INF directory, which undermines prior fixes intended to mitigate similar threats. Users of affected versions should update to the latest release to protect against potential exploitation.
Affected Version(s)
Crucible < 4.8.9
Fisheye < 4.8.9