Vulnerability Description
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Crucible | < 4.8.9 |
| Atlassian | Fisheye | < 4.8.9 |
Related Weaknesses (CWE)
References
- https://jira.atlassian.com/browse/CRUC-8520Issue TrackingVendor Advisory
- https://jira.atlassian.com/browse/FE-7384Issue TrackingVendor Advisory
- https://jira.atlassian.com/browse/CRUC-8520Issue TrackingVendor Advisory
- https://jira.atlassian.com/browse/FE-7384Issue TrackingVendor Advisory
FAQ
What is CVE-2021-43954?
CVE-2021-43954 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network ...
How severe is CVE-2021-43954?
CVE-2021-43954 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43954?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Crucible, Atlassian Fisheye.