-
Bug
-
Resolution: Fixed
-
Medium
-
4.7.1
-
Severity 3 - Minor
-
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.
- relates to
-
CRUC-8443 Improper authorization vulnerability in the /json/profile/removeStarAjax.do resource - CVE-2019-15009
-
- Closed
-
[FE-7252] Improper authorization vulnerability in the /json/profile/removeStarAjax.do resource - CVE-2019-15009
Labels | Original: CVE-2019-15009 advisory advisory-to-release cvss-medium improper-authorization security | New: CVE-2019-15009 advisory advisory-released cvss-medium improper-authorization security |
Security | Original: Atlassian Staff [ 10750 ] |
Labels | Original: CVE-2019-15009 advisory advisory-to-release cvss-medium security | New: CVE-2019-15009 advisory advisory-to-release cvss-medium improper-authorization security |
Summary | Original: Improper authorization vulnerability in the /json/profile/removeStarAjax.do resource | New: Improper authorization vulnerability in the /json/profile/removeStarAjax.do resource - CVE-2019-15009 |
Labels | Original: advisory advisory-to-release cvss-medium security | New: CVE-2019-15009 advisory advisory-to-release cvss-medium security |
Description | Original: The /json/profile/removeStarAjax.do resource in Atlassian Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability. | New: The /json/profile/removeStarAjax.do resource in Atlassian Fisheye before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability. |
Priority | Original: Low [ 4 ] | New: Medium [ 3 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Needs Triage [ 10030 ] | New: Closed [ 6 ] |
Component/s | New: Repositories [ 15590 ] | |
Component/s | Original: Projects [ 12952 ] | |
Fix Version/s | New: 4.8.0 [ 85591 ] | |
Fix Version/s | Original: 4.8.0 [ 85091 ] | |
Key |
Original:
|
New:
|
Affects Version/s | New: 4.7.1 [ 87092 ] | |
Affects Version/s | Original: 4.7.1 [ 87093 ] | |
Project | Original: Crucible [ 11771 ] | New: FishEye [ 11830 ] |
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 4.3 => Medium severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N