The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published: 2018-06-28T14:00:00Z

Updated: 2024-09-16T17:15:00.298Z

Reserved: 2017-11-16T00:00:00

Link: CVE-2017-16859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-06-28T14:29:00.213

Modified: 2018-08-23T11:38:23.537

Link: CVE-2017-16859

cve-icon Redhat

No data.