The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system.
| Software | From | Fixed in |
|---|---|---|
| atlassian / crucible | - | 4.4.0.x |
| atlassian / fisheye | - | 4.4.0.x |