Vulnerability Description
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Crucible | <= 4.4.0 |
| Atlassian | Fisheye | <= 4.4.0 |
Related Weaknesses (CWE)
References
- https://jira.atlassian.com/browse/CRUC-8053Vendor Advisory
- https://jira.atlassian.com/browse/FE-6892Vendor Advisory
- https://jira.atlassian.com/browse/CRUC-8053Vendor Advisory
- https://jira.atlassian.com/browse/FE-6892Vendor Advisory
FAQ
What is CVE-2017-9512?
CVE-2017-9512 is a vulnerability with a CVSS score of 7.5 (HIGH). The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committer...
How severe is CVE-2017-9512?
CVE-2017-9512 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9512?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Crucible, Atlassian Fisheye.