Lucene search

K
atlassianSecurity-metrics-botATLASSIAN:FE-7346
HistoryFeb 03, 2021 - 10:45 p.m.

Update application links to 5.4.23 to fix CVE-2020-5398

2021-02-0322:45:35
security-metrics-bot
jira.atlassian.com
48

0.625 Medium

EPSS

Percentile

97.9%

Affected versions of Atlassian FishEye and Crucible allow remote attackers to view sensitive information via an Information Disclosure vulnerability in a vulnerable version of the Application Links component.

The affected versions are before version 4.8.6.

Affected versions:

  • version < 4.8.6

Fixed versions:

  • 4.8.6
CPENameOperatorVersion
fisheyele4.7.0
fisheyele4.8.0
fisheyelt4.8.6