Vulnerabilities > Atlassian > Fisheye > 2.5.8

DATE CVE VULNERABILITY TITLE RISK
2020-06-01 CVE-2020-4015 Information Exposure vulnerability in Atlassian Crucible
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
network
low complexity
atlassian CWE-200
4.0
2020-06-01 CVE-2020-4014 Incorrect Authorization vulnerability in Atlassian Crucible
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
network
low complexity
atlassian CWE-863
4.0
2019-04-30 CVE-2018-20239 Cross-site Scripting vulnerability in Atlassian products
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter.
network
atlassian CWE-79
3.5