#VU15808 Privilege escalation in Atlassian Crucible and Atlassian Fisheye - CVE-2018-13399


| Updated: 2018-11-12

Vulnerability identifier: #VU15808

Vulnerability risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2018-13399

CWE-ID: CWE-264

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Atlassian Crucible
Client/Desktop applications / Office applications
Atlassian Fisheye
Client/Desktop applications / Office applications

Vendor: Atlassian

Description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists in Microsoft Windows Installer due to weak permissions on the installation directory. A local attacker can gain elevated privileges.

Mitigation
Update the affected software to versions 4.6.1, 4.7.0.

Vulnerable software versions

Atlassian Crucible: 4.0.0 - 4.6.0

Atlassian Fisheye: 4.0.0 - 4.6.0


External links
https://jira.atlassian.com/browse/CRUC-8314
https://jira.atlassian.com/browse/FE-7105


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability