Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-7397

CVE-2021-43955: /rest-service-fecru/server-v1 leaks information about installation directories

    • 5.7
    • Medium
    • CVE-2021-43955

      The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.

      Affected versions:

      • version < 4.8.9

      Fixed versions:

      • 4.8.9

            [FE-7397] CVE-2021-43955: /rest-service-fecru/server-v1 leaks information about installation directories

            Marek Parfianowicz made changes -
            Labels Original: CVE-2021-43955 advisory advisory-released advisory-to-release dont-import release-48x release-490 security New: CVE-2021-43955 advisory advisory-released advisory-to-release dont-import release-48x security
            Marek Parfianowicz made changes -
            Labels Original: CVE-2021-43955 advisory advisory-released advisory-to-release dont-import release-490 security New: CVE-2021-43955 advisory advisory-released advisory-to-release dont-import release-48x release-490 security
            Marek Parfianowicz made changes -
            Labels Original: CVE-2021-43955 advisory advisory-released advisory-to-release dont-import security New: CVE-2021-43955 advisory advisory-released advisory-to-release dont-import release-490 security
            Security Metrics Bot made changes -
            CVE ID New: CVE-2021-43955
            David Black made changes -
            Labels Original: advisory advisory-released advisory-to-release dont-import security New: CVE-2021-43955 advisory advisory-released advisory-to-release dont-import security
            David Black made changes -
            Labels Original: advisory advisory-to-release dont-import security New: advisory advisory-released advisory-to-release dont-import security
            David Black made changes -
            Resolution New: Fixed [ 1 ]
            Security Original: Atlassian Staff [ 10750 ]
            Status Original: Draft [ 12872 ] New: Published [ 12873 ]
            David Black made changes -
            Summary Original: /rest-service-fecru/server-v1 leaks information about installation directories New: CVE-2021-43955: /rest-service-fecru/server-v1 leaks information about installation directories
            David Black made changes -
            Description Original: The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability. New: The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.

            *Affected versions:*
             * version < 4.8.9

            *Fixed versions:*
             * 4.8.9
            David Black made changes -
            Description Original:
            This vulnerability affects certain versions of Atlassian Dev Tools. Please describe the impact of the vulnerability here. No known vulnerability could be read off of the parent.
            New: The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: