Lucene search

K
atlassianEjensbyATLASSIAN:FE-7164
HistoryFeb 14, 2019 - 10:03 p.m.

Fisheye had a vulnerable version of Apache Commons FileUpload - CVE-2016-1000031

2019-02-1422:03:17
ejensby
jira.atlassian.com
50

0.059 Low

EPSS

Percentile

93.5%

The DiskFileItem class from the Apache Commons FileUpload library before version 1.3.3 was vulnerable to CVE-2016-1000031. Atlassian Fisheye was using a vulnerable version of this library, although not the DiskFileItem class. Fisheye has been updated to use the safe version of the Apache Commons FileUpload library.

CPENameOperatorVersion
fisheyelt4.7.0
fisheyele4.2.3