CVE-2017-14591 is a vulnerability in Atlassian Crucible
Published on November 29, 2017
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
Products Associated with CVE-2017-14591
Want to know whenever a new CVE is published for Atlassian Crucible? stack.watch will email you.
Affected Versions
Atlassian Fisheye and Crucible Version Versions less than 4.4.3 OR version 4.5.0 is affected by CVE-2017-14591Exploit Probability
EPSS
0.65%
Percentile
70.52%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.