Medium severity4.3NVD Advisory· Published Mar 14, 2022· Updated Jun 17, 2026
CVE-2021-43954
CVE-2021-43954
Description
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6Patches
Vulnerability mechanics
References
2- jira.atlassian.com/browse/CRUC-8520nvdIssue TrackingVendor Advisory
- jira.atlassian.com/browse/FE-7384nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.