Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-43954

The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 49.6%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2021-43954


Contact Us

Shodan ® - All rights reserved