-
Bug
-
Resolution: Fixed
-
Low
-
4.8.0
-
Severity 3 - Minor
-
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a security misconfiguration.
- is related to
-
CRUC-8468 Security misconfiguration in the /json/fe/activeUserFinder.do resource - CVE-2020-4015
-
- Closed
-
[FE-7284] Security misconfiguration in the /json/fe/activeUserFinder.do resource - CVE-2020-4015
Labels | Original: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-48x release-490 security security-misconfiguration | New: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-48x security security-misconfiguration |
Labels | Original: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-490 security security-misconfiguration | New: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-48x release-490 security security-misconfiguration |
Labels | Original: advisory advisory-released bugbounty cve-2020-4015 cvss-medium security security-misconfiguration | New: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-490 security security-misconfiguration |
Fix Version/s | Original: 4.9.0 [ 90694 ] |
Labels | Original: advisory advisory-to-release bugbounty cve-2020-4015 cvss-medium security security-misconfiguration | New: advisory advisory-released bugbounty cve-2020-4015 cvss-medium security security-misconfiguration |
Due Date | Original: 16/Jul/2020 |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Closed [ 6 ] | New: Closed [ 6 ] |
Due Date | New: 16/Jul/2020 |
Labels | Original: advisory advisory-to-release bugbounty cvss-medium security security-misconfiguration | New: advisory advisory-to-release bugbounty cve-2020-4015 cvss-medium security security-misconfiguration |
Description | Original: Component in Atlassian Fisheye Crucible Development before version 4.8.1, 4.9.0 allows remote attackers to IMPACT via a VULN_INFO. | New: The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a security misconfiguration. |