Description
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-30816 | The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability. |
References
History
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2024-10-04T18:45:42.732Z
Reserved: 2021-11-16T00:00:00.000Z
Link: CVE-2021-43954
Updated: 2024-08-04T04:10:17.160Z
Status : Modified
Published: 2022-03-14T02:15:08.197
Modified: 2024-11-21T06:30:04.690
Link: CVE-2021-43954
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD