CVE-2021-43954

MEDIUM

Atlassian Crucible and Fisheye < 4.8.9 - Server-Side Request Forgery via DefaultRepositoryAdminService

Title source: llm
STIX 2.1

Description

The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/FE-7384
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/CRUC-8520

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 34.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
atlassian/crucible < 4.8.9
atlassian/fisheye < 4.8.9
Published Mar 14, 2022
Tracked Since Feb 18, 2026