The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2018-06-28T14:00:00Z
Updated: 2024-09-16T17:15:00.298Z
Reserved: 2017-11-16T00:00:00
Link: CVE-2017-16859
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-28T14:29:00.213
Modified: 2024-11-21T03:17:06.973
Link: CVE-2017-16859
Redhat
No data.