Description
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
References
https://jira.atlassian.com/browse/CRUC-8520
Issue TrackingVendor Advisory
https://jira.atlassian.com/browse/FE-7384
Issue TrackingVendor Advisory
https://jira.atlassian.com/browse/CRUC-8520
Issue TrackingVendor Advisory
https://jira.atlassian.com/browse/FE-7384
Issue TrackingVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-03-14T01:15:08.197Z
3 years agoLast modified
2024-11-21T05:30:04.690Z
1 year ago