CVE Database
/

CVE-2021-43957

Back to search

CVE-2021-43957

Published: Mar 16, 2022

Modified: Oct 4, 2024

PUBLISHED

Description

Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.

VendorProductVersions

Atlassian

Fisheye

affected
unspecified - < 4.8.9

Atlassian

Crucible

affected
unspecified - < 4.8.9

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now