CVE-2020-29446: Atlassian Crucible

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.

Affected products

  • Atlassian Crucible: before 4.8.5 (fixed in 4.8.5)
  • Atlassian Fisheye: before 4.8.5 (fixed in 4.8.5)

Published 2021-01-18. Last modified 2026-06-17.