Summary
The FishEye and Crucible plugins for JIRA are prone to an unspecified security vulnerability because they fail to properly handle crafted XML data.
Exploiting this issue allows remote attackers to cause denial-of- service conditions or to disclose local sensitive files in the context of an affected application.
FishEye and Crucible versions up to and including 2.7.11 are vulnerable.
Solution
Updates are available. Please see the references for more information.
References