vendor:
FishEye and Crucible plugins for JIRA
by:
SecurityFocus
7,5
CVSS
HIGH
Unspecified Security Vulnerability
N/A
CWE
Product Name: FishEye and Crucible plugins for JIRA
Affected Version From: FishEye and Crucible versions up to and including 2.7.11
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
FishEye and Crucible plugins for JIRA Security Vulnerability
The FishEye and Crucible plugins for JIRA are prone to an unspecified security vulnerability because they fail to properly handle crafted XML data. Exploiting this issue allows remote attackers to cause denial-of-service conditions or to disclose local sensitive files in the context of an affected application.
Mitigation:
Upgrade to FishEye and Crucible version 2.7.11 or later.