Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-18093

Опубликовано: 19 фев. 2018
Источник: nvd
CVSS3: 4.8
CVSS2: 3.5
EPSS Низкий

Описание

Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the location setting of a configured repository.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*
Версия от 4.4.0 (включая) до 4.4.3 (исключая)
Конфигурация 2
cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*
Версия от 4.4.0 (включая) до 4.4.3 (исключая)

EPSS

Процентиль: 39%
0.00177
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
github
больше 3 лет назад

Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the location setting of a configured repository.

EPSS

Процентиль: 39%
0.00177
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79