SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-43958

Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a…

CRITICAL 9.8EPSS 1.47%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via a improper restriction of excess authentication attempts vulnerability.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.47% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-307
Affected
atlassian/crucible · atlassian/fisheye
Source
security@atlassian.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.