Crucible
Vendor:
First CVE: May 22, 2012 · Active for 14 years
52
Total CVEs
More Total CVEs than 98% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Crucible over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2012
14 years ago
Most Recent CVE
May 21, 2024
798 days ago
CVE Severity & Scoring
Crucible52 CVEs
71%
19%
10%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.9%)
Network51 (98.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low51 (98.1%)
High1 (1.9%)
Unknown0 (0.0%)
User Interaction
None27 (51.9%)
Unknown0 (0.0%)
Required25 (48.1%)
Privileges Required
Low23 (44.2%)
High6 (11.5%)
None23 (44.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21683HIGH This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
This RCE (Remote Code Execution) vulnerability, wi | May 21, 2024 | 8.8 | 88 | NO | YES |
CVE-2012-2926CRITICAL Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo b | May 22, 2012 | 9.1 | 82 | NO | YES |
CVE-2022-26136CRITICAL A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which f | Jul 20, 2022 | 9.8 | 34 | NO | NO |
CVE-2017-16861CRITICAL It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. An attacker who can access the web interface of Fish | Feb 1, 2018 | 9.8 | 31 | NO | NO |
CVE-2021-43958CRITICAL Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were bey | Mar 16, 2022 | 9.8 | 30 | NO | NO |
CVE-2017-14591CRITICAL Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to ex | Nov 29, 2017 | 9.0 | 30 | NO | NO |
CVE-2022-26137HIGH A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests o | Jul 20, 2022 | 8.8 | 29 | NO | NO |
CVE-2020-4018HIGH The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerabili | Jun 1, 2020 | 8.8 | 27 | NO | NO |
CVE-2021-43957HIGH Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF direct | Mar 16, 2022 | 7.5 | 25 | NO | NO |
CVE-2018-5223HIGH Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attack | Mar 29, 2018 | 7.2 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (52 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.8% of CVEs· 97th percentile
Nuclei
1 CVE
1.9% of CVEs· 97th percentile
ExploitDB
1 CVE
1.9% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (52 CVEs).
Media Mentions
Signals from CVEs in this product scope (52 CVEs).
Top CNAs Publishing CVEs For Crucible
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.6.0 | 1 | 5.4 | 0.6% | 0 | 0 |
| 4.5.0 | 2 | 6.9 | 1.5% | 0 | 0 |
| 4.4.0 | 1 | 5.4 | 0.8% | 0 | 0 |
| 4.3.1 | 1 | 5.4 | 0.8% | 0 | 0 |