The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
2018-10-16T13:29:00.593
2024-11-21T03:47:01.730
Modified
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | atlassian | crucible | < 4.6.1 | Yes |
Application | atlassian | fisheye | < 4.6.1 | Yes |