atlassian crucible CVE-2021-43954 vulnerability in Atlassian Products
Published on March 14, 2022

The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.

NVD


Products Associated with CVE-2021-43954

stack.watch emails you whenever new vulnerabilities are published in Atlassian Crucible or Atlassian Fisheye. Just hit a watch button to start following.

 
 

Affected Versions

Atlassian Fisheye: Atlassian Crucible:

Exploit Probability

EPSS
0.14%
Percentile
34.36%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.