CVE-2020-4016
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/06/2020
Last modified:
21/07/2021
Description
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:* | 4.8.1 (excluding) | |
| cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:* | 4.8.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



