Lucene search

K
atlassian[email protected]ATLASSIAN:FE-7331
HistoryNov 19, 2020 - 12:08 a.m.

Remote Code Execution attack via unintentional expression in Freemarker tag - CVE-2017-12611

2020-11-1900:08:55
jira.atlassian.com
85

0.973 High

EPSS

Percentile

99.9%

Affected versions of Atlassian FishEye/Crucible allow remote attackers to execute arbitrary code via a Remote Code Execution (RCE) vulnerability via an unintentional expression in Freemarker tags, in Apache Struts.

The affected versions are before version 4.8.4.

Affected versions:

  • version < 4.8.4

Fixed versions:

  • 4.8.4
  • 4.9.0
CPENameOperatorVersion
fisheyele4.9.0
fisheyelt4.8.4