CVE-2017-9512

HIGH

Atlassian Fisheye/Crucible <4.4.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/CRUC-8053
Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/FE-6892

Scores

CVSS v3 7.5
EPSS 0.0116
EPSS Percentile 78.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
Atlassian/Atlassian Fisheye and Crucible All versions prior to version 4.4.1
atlassian/crucible < 4.4.0
atlassian/fisheye < 4.4.0
Published Aug 24, 2017
Tracked Since Feb 18, 2026