Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-6891

Anonymous local file system access on Windows OS - CVE-2017-9511

      The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.

      Workaround

      Create a $FISHEYE_INST\content directory, which can be empty but must exist.

      *Note: * This only affects windows versions.

            [FE-6891] Anonymous local file system access on Windows OS - CVE-2017-9511

            Owen made changes -
            Workflow Original: FE-CRUC Bug Workflow [ 2944981 ] New: JAC Bug Workflow v3 [ 2958938 ]
            Owen made changes -
            Workflow Original: FECRU Development Workflow - Triage - Restricted [ 2409599 ] New: FE-CRUC Bug Workflow [ 2944981 ]
            David Black made changes -
            Remote Link Original: This issue links to "Page (Extranet)" [ 314233 ]
            David Black made changes -
            Description Original: The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.

            h3. Workaround

            Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist.

            *Note: * This only affects windows versions.
            New: The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.

            h3. Workaround

            Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist.

            *Note: * This only affects windows versions.
            David Black made changes -
            Labels Original: CVE-2017-9511 ad advisory advisory-released cvss-high idor path-traversal security New: CVE-2017-9511 advisory advisory-released cvss-high idor path-traversal security
            David Black made changes -
            Labels Original: CVE-2017-9511 advisory-released cvss-high idor path-traversal security New: CVE-2017-9511 ad advisory advisory-released cvss-high idor path-traversal security
            David Black made changes -
            Labels Original: advisory-released cvss-high idor path-traversal security New: CVE-2017-9511 advisory-released cvss-high idor path-traversal security
            David Black made changes -
            Summary Original: Anonymous local file system access on Windows OS New: Anonymous local file system access on Windows OS - CVE-2017-9511
            David Black made changes -
            Description Original: An anonymous user with access to Crucible can access arbitrary files on the file system.
            h3. Workaround

            Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist.

            *Note: * This only affects windows versions.
            New: The MultiPathResource class in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to read read arbitrary files via a path traversal vulnerability when FishEye or Crucible are running on the Microsoft Windows operating system.

            h3. Workaround

            Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist.

            *Note: * This only affects windows versions.
            David Black made changes -
            Description Original: An anonymous user with access to Crucible can access arbitrary files on the file system.
            h3. Workaround

            Create {{$FISHEYE_INST\content}} directory, which can be empty but must exists.

            *Note: * This only affects windows versions.
            New: An anonymous user with access to Crucible can access arbitrary files on the file system.
            h3. Workaround

            Create a {{$FISHEYE_INST\content}} directory, which can be empty but must exist.

            *Note: * This only affects windows versions.

              Unassigned Unassigned
              pswiecicki Piotr Swiecicki
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: