Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-30819 Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 07 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2024-10-04T18:50:25.464Z

Reserved: 2021-11-16T00:00:00

Link: CVE-2021-43957

cve-icon Vulnrichment

Updated: 2024-08-04T04:10:17.200Z

cve-icon NVD

Status : Modified

Published: 2022-03-16T01:15:07.877

Modified: 2024-11-21T06:30:05.067

Link: CVE-2021-43957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.