Fisheye

Vendor:

First CVE: Dec 15, 2011 · Active for 14 years

52
Total CVEs
More Total CVEs than 98% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Fisheye over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2011
14 years ago
Most Recent CVE
May 21, 2024
797 days ago

CVE Severity & Scoring

Fisheye52 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local1 (1.9%)
Network50 (96.2%)
Unknown1 (1.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low50 (96.2%)
High1 (1.9%)
Unknown1 (1.9%)
User Interaction
None26 (50.0%)
Unknown1 (1.9%)
Required25 (48.1%)
Privileges Required
Low22 (42.3%)
High6 (11.5%)
None23 (44.2%)
Unknown1 (1.9%)

Top CVEs

Signals from CVEs in this product scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, wi
May 21, 20248.888NOYES
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo b
May 22, 20129.182NOYES
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which f
Jul 20, 20229.834NONO
It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. An attacker who can access the web interface of Fish
Feb 1, 20189.831NONO
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were bey
Mar 16, 20229.830NONO
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to ex
Nov 29, 20179.030NONO
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests o
Jul 20, 20228.829NONO
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerabili
Jun 1, 20208.827NONO
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF direct
Mar 16, 20227.525NONO
Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attack
Mar 29, 20187.225NONO

Exploit Exposure

Signals from CVEs in this product scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.8% of CVEs· 97th percentile
Nuclei
1 CVE
1.9% of CVEs· 97th percentile
ExploitDB
1 CVE
1.9% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (52 CVEs).

Media Mentions

Signals from CVEs in this product scope (52 CVEs).

Top CNAs Publishing CVEs For Fisheye

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.6.015.40.6%00
4.5.036.61.3%00
4.4.015.40.8%00
4.3.115.40.8%00
2.5.414.31.6%00
2.5.314.31.6%00
2.5.214.31.6%00
2.5.114.31.6%00
2.5.014.31.6%00
2.4.614.31.6%00
2.4.514.31.6%00
2.4.414.31.6%00
2.4.314.31.6%00
2.4.214.31.6%00
2.4.114.31.6%00
2.4.014.31.6%00
2.3.814.31.6%00
2.3.714.31.6%00
2.3.614.31.6%00
2.3.514.31.6%00