CVE Database
/

CVE-2017-9512

Back to search

CVE-2017-9512

Published: Aug 24, 2017

Modified: Oct 16, 2024

PUBLISHED

Description

The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.

VendorProductVersions

Atlassian

Atlassian Fisheye and Crucible

affected
All versions prior to version 4.4.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now