Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-6891

Anonymous local file system access on Windows OS - CVE-2017-9511

XMLWordPrintable

      The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.

      Workaround

      Create a $FISHEYE_INST\content directory, which can be empty but must exist.

      *Note: * This only affects windows versions.

            Unassigned Unassigned
            pswiecicki Piotr Swiecicki
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: