← Back

CVE-2017-14591

nvd nist
Published: Nov 29, 2017Modified: May 13, 2026

JSON object

Loading...
9.0
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD

Description

Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.

Affected (4)

2 products
Crucible
Fisheye
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Atlassian
Before 4.4.3
Version 4.5.0
Atlassian
Before 4.4.3
Version 4.5.0

References (4)

Source: security@atlassian.com
Third Party AdvisoryVDB Entry
Source: security@atlassian.com
Issue TrackingMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationVendor Advisory

Timeline

No history available yet.