atlassian crucible CVE-2021-43956 vulnerability in Atlassian Products
Published on March 16, 2022

The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.

NVD


Products Associated with CVE-2021-43956

stack.watch emails you whenever new vulnerabilities are published in Atlassian Crucible or Atlassian Fisheye. Just hit a watch button to start following.

 
 

Affected Versions

Atlassian Fisheye: Atlassian Crucible:

Exploit Probability

EPSS
0.37%
Percentile
58.33%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.