-
Bug
-
Resolution: Fixed
-
Low
-
None
-
None
-
Severity 3 - Minor
-
The mostActiveCommitters.do resource in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.
- was cloned as
-
CRUC-8053 mostActiveCommitters.do lacks permission checks - CVE-2017-9512
-
- Closed
-
[FE-6892] mostActiveCommitters.do lacks permission checks - CVE-2017-9512
Labels | Original: CVE-2017-9512 advisory-released cvss-medium security | New: CVE-2017-9512 advisory-released cvss-medium information-disclosure security |
Labels | Original: CVE-2017-9512 advisory-released cvss-medium patch-management security | New: CVE-2017-9512 advisory-released cvss-medium security |
Labels | Original: CVE-2017-9512 advisory-released cvss-medium security | New: CVE-2017-9512 advisory-released cvss-medium patch-management security |
Workflow | Original: FE-CRUC Bug Workflow [ 2944979 ] | New: JAC Bug Workflow v3 [ 2957225 ] |
Workflow | Original: FECRU Development Workflow - Triage - Restricted [ 2409600 ] | New: FE-CRUC Bug Workflow [ 2944979 ] |
Remote Link | Original: This issue links to "Page (Extranet)" [ 314231 ] |
Description | Original: The mostActiveCommitters.do resource in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses and other committer information, as it lacked permission checks. | New: The mostActiveCommitters.do resource in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks. |
Labels | Original: advisory-released cvss-medium security | New: CVE-2017-9512 advisory-released cvss-medium security |
Summary | Original: mostActiveCommitters.do available to anonymous users | New: mostActiveCommitters.do lacks permission checks - CVE-2017-9512 |
Description | Original: Anonymous users have access to the mostActiveCommitters.do which leaks some sensitive information (such as email addresses). | New: The mostActiveCommitters.do resource in Atlassian FishEye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses and other committer information, as it lacked permission checks. |