The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2017-9232 | The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2024-09-16T17:28:59.763Z
Reserved: 2018-02-01T00:00:00
Link: CVE-2017-18095

No data.

Status : Modified
Published: 2018-02-19T14:29:00.520
Modified: 2024-11-21T03:19:21.053
Link: CVE-2017-18095

No data.

No data.