CVE-2018-13399

HIGH

Atlassian Crucible and Fisheye < 4.6.1 - Privilege Escalation via Weak Installation Directory Permissions

Title source: llm
STIX 2.1

Description

The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://jira.atlassian.com/browse/FE-7105
Issue Tracking, Vendor Advisory x_refsource_confirm
https://jira.atlassian.com/browse/CRUC-8314

Scores

CVSS v3 7.8
EPSS 0.0026
EPSS Percentile 16.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (2)
atlassian/crucible < 4.6.1
atlassian/fisheye < 4.6.1
Published Oct 16, 2018
Tracked Since Feb 18, 2026