Lucene search

K
atlassian[email protected]ATLASSIAN:CRUC-8497
HistoryNov 17, 2020 - 10:21 p.m.

Remote Code Execution attack via unintentional expression in Freemarker tag - CVE-2017-12611

2020-11-1722:21:28
jira.atlassian.com
116
atlassian
fisheye
crucible
remote code execution
vulnerability
apache struts
freemarker
4.8.4
4.9.0

EPSS

0.973

Percentile

99.9%

Affected versions of Atlassian FishEye/Crucible allow remote attackers to execute arbitrary code via a Remote Code Execution (RCE) vulnerability via an unintentional expression in Freemarker tags, in Apache Struts.

The affected versions are before version 4.8.4.

Affected versions:

  • version < 4.8.4

Fixed versions:

  • 4.8.4
  • 4.9.0