CVE-2018-13399

HIGH

Atlassian Crucible < 4.6.1 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://jira.atlassian.com/browse/FE-7105
Issue Tracking, Vendor Advisory x_refsource_confirm
https://jira.atlassian.com/browse/CRUC-8314

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 6.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (2)
atlassian/crucible < 4.6.1
atlassian/fisheye < 4.6.1
Published Oct 16, 2018
Tracked Since Feb 18, 2026