Uploaded image for project: 'Crucible'
  1. Crucible
  2. CRUC-8049

Anonymous local file system access on Windows OS - CVE-2017-9511

    XMLWordPrintable

Details

    Description

      The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.

      Workaround

      Create $FISHEYE_INST\content directory, which can be empty but must exists.

      *Note: * This only affects windows versions - I tested on OSX and it is not vulnerable to this issue.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              pswiecicki Piotr Swiecicki
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: