Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5p26-vm69-mjxq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.

The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.

EPSS

Процентиль: 48%
0.00253
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
больше 5 лет назад

The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.

EPSS

Процентиль: 48%
0.00253
Низкий

Дефекты

CWE-863