Vulnerabilities > Atlassian > Crucible > 4.4.1

DATE CVE VULNERABILITY TITLE RISK
2017-11-29 CVE-2017-14591 Argument Injection or Modification vulnerability in Atlassian Crucible and Fisheye
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
network
atlassian CWE-88
critical
9.3
2017-10-11 CVE-2017-14588 Cross-site Scripting vulnerability in Atlassian Crucible
Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.
network
atlassian CWE-79
4.3
2017-10-11 CVE-2017-14587 Cross-site Scripting vulnerability in Atlassian Crucible
The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.
network
atlassian CWE-79
3.5