MEDIUM
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability
Published Jun 1, 2020
4.3
MEDIUMCVSS 3.1
EPSS 0.77%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.