Vulnerabilities > CVE-2017-18035 - Missing Authorization vulnerability in Atlassian Fisheye

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
atlassian
CWE-862

Summary

The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for it.

Vulnerable Configurations

Part Description Count
Application
Atlassian
377

Common Weakness Enumeration (CWE)