Description
The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-9175 | The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for it. |
References
History
No history.
Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2024-09-16T23:30:24.222Z
Reserved: 2018-01-17T00:00:00.000Z
Link: CVE-2017-18035
No data.
Status : Modified
Published: 2018-02-02T14:29:00.607
Modified: 2024-11-21T03:19:13.130
Link: CVE-2017-18035
No data.
OpenCVE Enrichment
No data.
EUVD