CVE-2017-9512
24.08.2017, 17:29
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.Enginsight
| Vendor | Product | Version |
|---|---|---|
| atlassian | crucible | 𝑥 ≤ 4.4.0 |
| atlassian | fisheye | 𝑥 ≤ 4.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration