CVE-2020-29447

Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews. The affected versions are before version 4.7.4, and from version 4.8.0 before 4.8.5.
References
Link Resource
https://jira.atlassian.com/browse/CRUC-8505 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-12-21 01:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-29447

Mitre link : CVE-2020-29447

CVE.ORG link : CVE-2020-29447


JSON object : View

Products Affected

atlassian

  • crucible
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type