CVE-2020-14191: Atlassian Crucible

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4.

Affected products

  • Atlassian Crucible: before 4.8.4 (fixed in 4.8.4)
  • Atlassian Fisheye: before 4.8.4 (fixed in 4.8.4)

Published 2020-11-25. Last modified 2026-06-17.