CVE-2012-2926
CVE-2012-2926
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/37218unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://confluence.atlassian.com/display/BAMBOO/Bamboo+Security+Advisory+2012-05-17http://confluence.atlassian.com/display/CROWD/Crowd+Security+Advisory+2012-05-17http://confluence.atlassian.com/display/DOC/Confluence+Security+Advisory+2012-05-17http://confluence.atlassian.com/display/FISHEYE/FishEye+and+Crucible+Security+Advisory+2012-05-17http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2012-05-17http://osvdb.org/81993http://secunia.com/advisories/49146https://exchange.xforce.ibmcloud.com/vulnerabilities/75682https://exchange.xforce.ibmcloud.com/vulnerabilities/75697http://www.securityfocus.com/bid/53595