-
Bug
-
Resolution: Fixed
-
High
-
None
-
None
-
Severity 3 - Minor
-
The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.
Workaround
Create a $FISHEYE_INST\content directory, which can be empty but must exist.
*Note: * This only affects windows versions.
- is cloned from
-
CRUC-8049 Anonymous local file system access on Windows OS - CVE-2017-9511
-
- Closed
-
[FE-6891] Anonymous local file system access on Windows OS - CVE-2017-9511
Workflow | Original: FE-CRUC Bug Workflow [ 2944981 ] | New: JAC Bug Workflow v3 [ 2958938 ] |
Workflow | Original: FECRU Development Workflow - Triage - Restricted [ 2409599 ] | New: FE-CRUC Bug Workflow [ 2944981 ] |
Remote Link | Original: This issue links to "Page (Extranet)" [ 314233 ] |
Description |
Original:
The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.
h3. Workaround Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist. *Note: * This only affects windows versions. |
New:
The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.
h3. Workaround Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist. *Note: * This only affects windows versions. |
Labels | Original: CVE-2017-9511 ad advisory advisory-released cvss-high idor path-traversal security | New: CVE-2017-9511 advisory advisory-released cvss-high idor path-traversal security |
Labels | Original: CVE-2017-9511 advisory-released cvss-high idor path-traversal security | New: CVE-2017-9511 ad advisory advisory-released cvss-high idor path-traversal security |
Labels | Original: advisory-released cvss-high idor path-traversal security | New: CVE-2017-9511 advisory-released cvss-high idor path-traversal security |
Summary | Original: Anonymous local file system access on Windows OS | New: Anonymous local file system access on Windows OS - CVE-2017-9511 |
Description |
Original:
An anonymous user with access to Crucible can access arbitrary files on the file system.
h3. Workaround Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist. *Note: * This only affects windows versions. |
New:
The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.
h3. Workaround Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist. *Note: * This only affects windows versions. |
Description |
Original:
An anonymous user with access to Crucible can access arbitrary files on the file system.
h3. Workaround Create {{$FISHEYE_INST\content}} directory, which can be empty but must exists. *Note: * This only affects windows versions. |
New:
An anonymous user with access to Crucible can access arbitrary files on the file system.
h3. Workaround Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist. *Note: * This only affects windows versions. |