CVE-2017-14591
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
- CVSS 3.0
- 9.0 CRITICALCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-88
- Affected
- atlassian/crucible · atlassian/fisheye
- Source
- security@atlassian.com
References
- http://www.securityfocus.com/bid/102194Third Party Advisory, VDB Entry
- https://confluence.atlassian.com/x/plcGOIssue Tracking, Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/102194Third Party Advisory, VDB Entry
- https://confluence.atlassian.com/x/plcGOIssue Tracking, Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.