CVE-2021-43954
14.03.2022, 02:15
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
Vendor | Product | Version |
---|---|---|
atlassian | crucible | 𝑥 < 4.8.9 |
atlassian | fisheye | 𝑥 < 4.8.9 |
𝑥
= Vulnerable software versions