Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://jira.atlassian.com/browse/CRUC-8498 | vendor advisory issue tracking patch |
https://jira.atlassian.com/browse/FE-7336 | vendor advisory issue tracking patch |