Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://jira.atlassian.com/browse/FE-7334 | vendor advisory issue tracking |
https://jira.atlassian.com/browse/CRUC-8502 | vendor advisory issue tracking |