CVE-2020-29446
CVE-2020-29446: 2 tracked advisory records across Atlassian. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Atlassian
2 advisories- Advisory severityHigh7.5
High [CVE-2020-29446 +1] Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files
CVE-2021-43957Source published Source updated
This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.
- Related products — impact not confirmed
- Fisheye
- Crucible
- Source-reported affected versions
- 4.8.9
- Source-reported fixed versions
- 4.8.9
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
- Advisory severityMedium5.3
Medium [CVE-2020-29446] Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files
CVE-2020-29446Source published Source updated
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.
- Related products — impact not confirmed
- Fisheye
- Crucible
- Source-reported affected versions
- 4.8.5
- Source-reported fixed versions
- 4.8.5
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Atlassian CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.