-
Bug
-
Resolution: Fixed
-
Medium
-
None
-
None
-
Severity 2 - Major
-
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
- was cloned as
-
CRUC-8314 Weak permissions on the installation directory - CVE-2018-13399
-
- Closed
-
[FE-7105] Weak permissions on the installation directory - CVE-2018-13399
Link | New: This issue supersedes FE-7216 [ FE-7216 ] |
Fix Version/s | Original: 4.7.0 [ 81794 ] |
Workflow | Original: FE-CRUC Bug Workflow [ 2945180 ] | New: JAC Bug Workflow v3 [ 2957472 ] |
Workflow | Original: FECRU Development Workflow - Triage - Restricted [ 2859989 ] | New: FE-CRUC Bug Workflow [ 2945180 ] |
Labels | Original: CVE-2018-13399 advisory advisory-to-release basm bugbounty cvss-medium privesc security | New: CVE-2018-13399 advisory advisory-released basm bugbounty cvss-medium privesc security |
Security | Original: Reporter and Atlassian Staff [ 10751 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Open [ 1 ] | New: Closed [ 6 ] |
Due Date | New: 23/Nov/2018 |
Resolution | Original: Fixed [ 1 ] | |
Status | Original: Closed [ 6 ] | New: Open [ 1 ] |
Description | Original: The Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory. | New: The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory. |