Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
| Software | From | Fixed in |
|---|---|---|
| atlassian / crucible | - | 4.4.3 |
| atlassian / fisheye | - | 4.4.3 |
| atlassian / fisheye | 4.5.0 | 4.5.0.x |
| atlassian / crucible | 4.5.0 | 4.5.0.x |