CVE-2020-14192: Atlassian Crucible

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.

Affected products

  • Atlassian Crucible: before 4.8.4 (fixed in 4.8.4)
  • Atlassian Fisheye: before 4.8.4 (fixed in 4.8.4)

Published 2021-02-02. Last modified 2026-06-17.