Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-7284

Security misconfiguration in the /json/fe/activeUserFinder.do resource - CVE-2020-4015

      The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a security misconfiguration.

            [FE-7284] Security misconfiguration in the /json/fe/activeUserFinder.do resource - CVE-2020-4015

            Marek Parfianowicz made changes -
            Labels Original: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-48x release-490 security security-misconfiguration New: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-48x security security-misconfiguration
            Marek Parfianowicz made changes -
            Labels Original: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-490 security security-misconfiguration New: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-48x release-490 security security-misconfiguration
            Marek Parfianowicz made changes -
            Labels Original: advisory advisory-released bugbounty cve-2020-4015 cvss-medium security security-misconfiguration New: advisory advisory-released bugbounty cve-2020-4015 cvss-medium release-490 security security-misconfiguration
            Marek Parfianowicz made changes -
            Fix Version/s Original: 4.9.0 [ 90694 ]
            Erin Jensby made changes -
            Labels Original: advisory advisory-to-release bugbounty cve-2020-4015 cvss-medium security security-misconfiguration New: advisory advisory-released bugbounty cve-2020-4015 cvss-medium security security-misconfiguration
            David Black made changes -
            Due Date Original: 16/Jul/2020
            David Black made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Closed [ 6 ] New: Closed [ 6 ]
            Security Metrics Bot made changes -
            Due Date New: 16/Jul/2020
            Erin Jensby made changes -
            Labels Original: advisory advisory-to-release bugbounty cvss-medium security security-misconfiguration New: advisory advisory-to-release bugbounty cve-2020-4015 cvss-medium security security-misconfiguration
            Erin Jensby made changes -
            Description Original: Component in Atlassian Fisheye Crucible Development before version 4.8.1, 4.9.0 allows remote attackers to IMPACT via a VULN_INFO. New: The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a security misconfiguration.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: