Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-7387

CVE-2021-43958: Various rest resources missing CAPTCHA for failed user login attempts

    • 7.4
    • High
    • CVE-2021-43958

      Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via a improper restriction of excess authentication attempts vulnerability.

      Affected versions:

      • version < 4.8.9

      Fixed versions:

      • 4.8.9

            [FE-7387] CVE-2021-43958: Various rest resources missing CAPTCHA for failed user login attempts

            Marek Parfianowicz made changes -
            Labels Original: CVE-2021-43958 advisory advisory-released dont-import release-48x release-490 security New: CVE-2021-43958 advisory advisory-released dont-import release-48x security
            Marek Parfianowicz made changes -
            Labels Original: CVE-2021-43958 advisory advisory-released dont-import release-490 security New: CVE-2021-43958 advisory advisory-released dont-import release-48x release-490 security
            Marek Parfianowicz made changes -
            Labels Original: CVE-2021-43958 advisory advisory-released dont-import security New: CVE-2021-43958 advisory advisory-released dont-import release-490 security
            Security Metrics Bot made changes -
            CVE ID New: CVE-2021-43958
            David Black made changes -
            Remote Link New: This issue links to "VULN-564011 (Atlassian Security Jira)" [ 627256 ]
            David Black made changes -
            Link New: This issue is related to CRUC-8522 [ CRUC-8522 ]
            David Black made changes -
            Link New: This issue is related to FE-7386 [ FE-7386 ]
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release dont-import security New: CVE-2021-43958 advisory advisory-released dont-import security
            David Black made changes -
            Description Original: Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via a improper restriction of excess authentication attempts vulnerability. New: Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via a improper restriction of excess authentication attempts vulnerability.

            *Affected versions:*
             * version < 4.8.9

            *Fixed versions:*
             * 4.8.9

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: