Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-6891

Anonymous local file system access on Windows OS - CVE-2017-9511

    XMLWordPrintable

    Details

      Description

      The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.

      Workaround

      Create a $FISHEYE_INST\content directory, which can be empty but must exist.

      *Note: * This only affects windows versions.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned Unassigned
              Reporter:
              pswiecicki Piotr Swiecicki
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: