-
Bug
-
Resolution: Fixed
-
Low
-
4.8.3
-
Severity 2 - Major
-
Affected version of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL.
The affected versions are before version 4.8.4.
Affected versions:
- version < 4.8.4
Fixed versions:
- 4.8.4
- 4.9.0
- is cloned from
-
CRUC-8498 A user-supplied regex in EyeQL causes ReDoS - CVE-2020-14190
-
- Closed
-
[FE-7336] A user-supplied regex in EyeQL causes ReDoS - CVE-2020-14190
Labels | Original: CVE-2020-14190 advisory advisory-to-release cvss-medium release-48x release-490 security | New: CVE-2020-14190 advisory advisory-to-release cvss-medium release-48x security |
Labels | Original: CVE-2020-14190 advisory advisory-to-release cvss-medium release-490 security | New: CVE-2020-14190 advisory advisory-to-release cvss-medium release-48x release-490 security |
Labels | Original: CVE-2020-14190 advisory advisory-to-release cvss-medium security | New: CVE-2020-14190 advisory advisory-to-release cvss-medium release-490 security |
Fix Version/s | Original: 4.9.0 [ 90694 ] |
Summary | Original: A user-supplied regex in EyeQL causes ReDoS - CVE-PENDING | New: A user-supplied regex in EyeQL causes ReDoS - CVE-2020-14190 |
Labels | Original: advisory advisory-to-release cve-in-progress cvss-medium security | New: CVE-2020-14190 advisory advisory-to-release cvss-medium security |
Summary | Original: A user-supplied regex in EyeQL causes ReDoS | New: A user-supplied regex in EyeQL causes ReDoS - CVE-PENDING |
Description |
Original:
Affected version of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL.
The affected versions are before version 4.8.4. CVE Pending. *Affected versions:* * version < 4.8.4 *Fixed versions:* * 4.8.4 * 4.9.0 |
New:
Affected version of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL.
The affected versions are before version 4.8.4. *Affected versions:* * version < 4.8.4 *Fixed versions:* * 4.8.4 * 4.9.0 |
Description |
Original:
Affected version of Atlassian FishEye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL.
The affected versions are before version 4.8.4. CVE Pending. *Affected versions:* * version < 4.8.4 *Fixed versions:* * 4.8.4 * 4.9.0 |
New:
Affected version of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL.
The affected versions are before version 4.8.4. CVE Pending. *Affected versions:* * version < 4.8.4 *Fixed versions:* * 4.8.4 * 4.9.0 |
Labels | Original: advisory cve-in-progress cvss-medium security | New: advisory advisory-to-release cve-in-progress cvss-medium security |