VYPR
High severity7.5NVD Advisory· Published Aug 24, 2017· Updated May 13, 2026

CVE-2017-9512

CVE-2017-9512

Description

The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.

Affected products

3
  • cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*
    Range: <=4.4.0
  • cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*
    Range: <=4.4.0
  • Atlassian/Atlassian Fisheye and Cruciblev5
    Range: All versions prior to version 4.4.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.