CVE-2020-29447: Atlassian Crucible

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews. The affected versions are before version 4.7.4, and from version 4.8.0 before 4.8.5.

Affected products

  • Atlassian Crucible: before 4.7.4 (fixed in 4.7.4); from 4.8.0, before 4.8.5 (fixed in 4.8.5)

Published 2020-12-21. Last modified 2026-06-17.