Uploaded image for project: 'Crucible'
  1. Crucible
  2. CRUC-8212

Path traversal Vulnerability in the review attachment resource - CVE-2017-16859

      The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.

            [CRUC-8212] Path traversal Vulnerability in the review attachment resource - CVE-2017-16859

            Richard Atkins made changes -
            Labels Original: CVE-2017-16859 advisory advisory-released cvss-high path-traversal security New: CVE-2017-16859 advisory advisory-released cvss-high idor path-traversal security
            Owen made changes -
            Workflow Original: FE-CRUC Bug Workflow [ 2939407 ] New: JAC Bug Workflow v3 [ 2952580 ]
            Owen made changes -
            Workflow Original: FECRU Development Workflow - Triage - Restricted [ 2706142 ] New: FE-CRUC Bug Workflow [ 2939407 ]
            David Black made changes -
            Labels Original: CVE-2017-16859 advisory advisory-to-release cvss-high path-traversal security New: CVE-2017-16859 advisory advisory-released cvss-high path-traversal security
            David Black made changes -
            Labels Original: advisory advisory-to-release cvss-high path-traversal security New: CVE-2017-16859 advisory advisory-to-release cvss-high path-traversal security
            David Black made changes -
            Link New: This issue was cloned as CRUC-8213 [ CRUC-8213 ]
            David Black made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Summary Original: Path traversal Vulnerability in the review attachment resource - CVE-PENDING New: Path traversal Vulnerability in the review attachment resource - CVE-2017-16859
            David Black made changes -
            Summary Original: Path traversal Vulnerability in Crucible Upload - CVE-PENDING New: Path traversal Vulnerability in the review attachment resource - CVE-PENDING
            David Black made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Needs Triage [ 10030 ] New: Closed [ 6 ]

              Unassigned Unassigned
              mtokarski@atlassian.com Marek Tokarski
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: