{"api_version":"1","generated_at":"2026-07-23T07:15:33+00:00","cve":"CVE-2017-18095","urls":{"html":"https://cve.report/CVE-2017-18095","api":"https://cve.report/api/cve/CVE-2017-18095.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-18095","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-18095"},"summary":{"title":"CVE-2017-18095","description":"The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.","state":"PUBLIC","assigner":"security@atlassian.com","published_at":"2018-02-19 14:29:00","updated_at":"2019-10-09 23:25:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/103207","name":"103207","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Atlassian Crucible CVE-2017-18095 Remote Authorization Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://jira.atlassian.com/browse/CRUC-8178","name":"https://jira.atlassian.com/browse/CRUC-8178","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"[CRUC-8178] Improper authorization vulnerability in SnippetRPCServiceImpl allowing user's to comment on snippets they are not authorised to access -  CVE-2017-18095 - Create and track feature requests for Atlassian products.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-18095","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-18095","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"18095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"crucible","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18095","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"crucible","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@atlassian.com","DATE_PUBLIC":"2018-02-19T00:00:00","ID":"CVE-2017-18095","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Crucible","version":{"version_data":[{"version_value":"prior to 4.5.1"},{"version_value":"prior to 4.6.0"}]}}]},"vendor_name":"Atlassian"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Incorrect Authorization (CWE-863)"}]}]},"references":{"reference_data":[{"name":"103207","refsource":"BID","url":"http://www.securityfocus.com/bid/103207"},{"name":"https://jira.atlassian.com/browse/CRUC-8178","refsource":"CONFIRM","url":"https://jira.atlassian.com/browse/CRUC-8178"}]}},"nvd":{"publishedDate":"2018-02-19 14:29:00","lastModifiedDate":"2019-10-09 23:25:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*","versionEndExcluding":"4.5.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"18095","Ordinal":"122588","Title":"CVE-2017-18095","CVE":"CVE-2017-18095","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"18095","Ordinal":"1","NoteData":"The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"18095","Ordinal":"2","NoteData":"2018-02-19","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"18095","Ordinal":"3","NoteData":"2018-03-06","Type":"Other","Title":"Modified"}]}}}