← Back

Crucible

crucible

Vendor: Atlassian • 52 CVEs

CVEs (52)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
2Crucible
Fisheye
Jun 17, 2026
Dec 11, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerabi...Show more
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.Show less
1Atlassian
2Crucible
Fisheye
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the revie...Show more
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.Show less
1Atlassian
2Crucible
Fisheye
Jun 17, 2026
Dec 11, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branc...Show more
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.Show less
1Atlassian
8Bamboo
BitbucketConfluence+5 more
Jun 17, 2026
Nov 8, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorizat...Show more
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.Show less
1Atlassian
8Application Links
Confluence Data CenterConfluence Server+5 more
Nov 21, 2024
Apr 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrar...Show more
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a plugin in various Atlassian products where the following are affected: Confluence before version 6.15.2, Crucible before version 4.7.0, Crowd before version 3.4.3, Fisheye before version 4.7.0, Jira before version 7.13.3 and 8.x before 8.1.0.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Feb 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser par...Show more
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Feb 20, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href par...Show more
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Oct 16, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Sep 18, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Aug 13, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Jul 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Jun 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the r...Show more
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Apr 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response h...Show more
The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Mar 29, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repositor...Show more
Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repository in Fisheye or Crucible can execute code of their choice on systems that run a vulnerable version of Fisheye or Crucible on the Windows operating system. All versions of Fisheye and Crucible before 4.4.6 (the fixed version for 4.4.x) and from 4.5.0 before 4.5.3 (the fixed version for 4.5.x) are affected by this vulnerability.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Mar 22, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross si...Show more
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the base path setting of a configured file system repository.Show less
1Atlassian
1Crucible
Nov 21, 2024
Feb 19, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an imprope...Show more
The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Feb 19, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or...Show more
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the location setting of a configured repository.Show less
1Atlassian
1Crucible
Nov 21, 2024
Feb 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnera...Show more
The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of a comment on the snippet.Show less
1Atlassian
2Crucible
Fisheye
Nov 21, 2024
Feb 16, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or Jav...Show more
The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the filename of a backup.Show less
1Atlassian
1Crucible
Nov 21, 2024
Feb 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerab...Show more
The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.Show less