Overview :
DoS vulnerability in the file upload request feature of Atlassian Crucible
Affected Product(s) :
  • version < 4.7.4
  • 4.8.0 ≤ version < 4.8.5
Vulnerability Details :
CVE ID : CVE-2020-29447
Affected versions of Atlassian Crucible allow remote attackers to impact the application’s availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews.

Solution :

Upgrade to versions :-

  • 4.7.4
  • 4.8.5
  • 4.9.0