Anonymous local file system access on Windows OS - CVE-2017-9511

XMLWordPrintable

    • Severity 3 - Minor

      The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.

      Workaround

      Create a $FISHEYE_INST\content directory, which can be empty but must exist.

      *Note: * This only affects windows versions.

            Assignee:
            Unassigned
            Reporter:
            Piotr Swiecicki
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: