CVE-2021-43954
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request…
Does this matter?
Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.
Description
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.77% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- atlassian/crucible · atlassian/fisheye
- Source
- security@atlassian.com
References
- https://jira.atlassian.com/browse/CRUC-8520Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/FE-7384Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/CRUC-8520Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/FE-7384Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.