Unrated severityNVD Advisory· Published Feb 2, 2018· Updated Sep 16, 2024
CVE-2017-18035
CVE-2017-18035
Description
The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for it.
Affected products
1- Range: prior to 4.5.1 and 4.6.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jira.atlassian.com/browse/CRUC-8163mitrex_refsource_CONFIRM
- jira.atlassian.com/browse/FE-6996mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.