Vulnerabilities > CVE-2020-29446 - Authorization Bypass Through User-Controlled Key vulnerability in Atlassian Crucible

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
atlassian
CWE-639

Summary

Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.

Vulnerable Configurations

Part Description Count
Application
Atlassian
408