-
Public Security Vulnerability
-
Resolution: Fixed
-
Low
-
4.8.8
-
None
-
6.1
-
Medium
-
CVE-2021-43956
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
Affected versions:
- version < 4.8.9
Fixed versions:
- 4.8.9
- is related to
-
CRUC-8531 CVE-2021-43956: Javascript Prototype Pollution in the jQuery deserialize library
-
- Published
-
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 6.1 => Medium severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N