The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for it.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-9175 The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for it.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2024-09-16T23:30:24.222Z

Reserved: 2018-01-17T00:00:00

Link: CVE-2017-18035

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-02T14:29:00.607

Modified: 2024-11-21T03:19:13.130

Link: CVE-2017-18035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.