ZeroHour

CVE-2017-9512

CVSS 3.1
7.5 high
EPSS
2%p79
Published
()
Modified
Description

The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.

Vendors
atlassian
Products
crucible, fisheye
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.