CVE-2021-43956 vulnerability in Atlassian Products
Published on March 16, 2022
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
Products Associated with CVE-2021-43956
stack.watch emails you whenever new vulnerabilities are published in Atlassian Crucible or Atlassian Fisheye. Just hit a watch button to start following.
Affected Versions
Atlassian Fisheye:- Version unspecified and below 4.8.9 is affected.
- Version unspecified and below 4.8.9 is affected.
Exploit Probability
EPSS
0.37%
Percentile
58.33%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.