Lucene search

K
atlassianEjensbyATLASSIAN:CRUC-8382
HistoryFeb 14, 2019 - 9:59 p.m.

Crucible had a vulnerable version of Apache Commons FileUpload - CVE-2016-1000031

2019-02-1421:59:23
ejensby
jira.atlassian.com
14

0.059 Low

EPSS

Percentile

93.5%

The DiskFileItem class from the Apache Commons FileUpload library before version 1.3.3 was vulnerable to CVE-2016-1000031.  Atlassian Crucible was using a vulnerable version of this library, although not the DiskFileItem class.  Crucible has been updated to use the safe version of the Apache Commons FileUpload library.

CPENameOperatorVersion
cruciblelt4.7.0
cruciblele4.2.3