Uploaded image for project: 'Crucible'
  1. Crucible
  2. CRUC-8482

XSS in the review coverage resource through the committerFilter parameter- CVE-2020-4023

      The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.

      Affected versions:

      • version < 4.8.2

      Fixed versions:

      • 4.8.2
      • 4.9.0

            [CRUC-8482] XSS in the review coverage resource through the committerFilter parameter- CVE-2020-4023

            Marek Parfianowicz made changes -
            Labels Original: CVE-2020-4023 advisory advisory-released bugbounty cvss-high release-48x release-490 security xss New: CVE-2020-4023 advisory advisory-released bugbounty cvss-high release-48x security xss
            Marek Parfianowicz made changes -
            Labels Original: CVE-2020-4023 advisory advisory-released bugbounty cvss-high release-490 security xss New: CVE-2020-4023 advisory advisory-released bugbounty cvss-high release-48x release-490 security xss
            Marek Parfianowicz made changes -
            Labels Original: CVE-2020-4023 advisory advisory-released bugbounty cvss-high security xss New: CVE-2020-4023 advisory advisory-released bugbounty cvss-high release-490 security xss
            Marek Parfianowicz made changes -
            Fix Version/s Original: 4.9.0 [ 90696 ]
            David Black made changes -
            Labels Original: CVE-2020-4023 advisory advisory-to-release bugbounty cvss-high security xss New: CVE-2020-4023 advisory advisory-released bugbounty cvss-high security xss
            David Black made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Link New: This issue is related to CRUC-8483 [ CRUC-8483 ]
            David Black made changes -
            Link Original: This issue was cloned as CRUC-8483 [ CRUC-8483 ]
            David Black made changes -
            Priority Original: Low [ 4 ] New: Medium [ 3 ]
            David Black made changes -
            Link New: This issue was cloned as CRUC-8483 [ CRUC-8483 ]

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: