CVE-2021-43954

CVE-2021-43954

The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have ‘can add repository permission’, to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.

Source: CVE-2021-43954

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다