Atlassian FishEye/Crucible XSS Vulnerability (CVE-2017-18094)
Atlassian FishEye/Crucible XSS Vulnerability (CVE-2017-18094)
Release date:
Updated on:
Affected Systems:
Atlassian Fisheye <4.4.3
Atlassian Fisheye 4.5.0
Atlassian Crucible <4.4.3
Atlassian Crucible 4.5.0
Description:
Bugtraq id: 103499
CVE (CAN) ID: CVE-2017-18094
Atlassian FishEye can search, track, and visualize code changes. Crucible allows collaborative code reviews.
Versions earlier than Atlassian Fisheye/Crucible 4.4.3 and 4.5.0 have security vulnerabilities in multiple resource implementations, allowing remote attackers to exploit this vulnerability to inject arbitrary HTML or JavaScript.
<* Source: vendor
*>
Suggestion:
Vendor patch:
Atlassian
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.atlassian.com/
Https://jira.atlassian.com/browse/CRUC-8177
Https://jira.atlassian.com/browse/FE-7010
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151589.htm