Atlassian Crowd XML External Entity Information Disclosure Vulnerability
BID:60899
Info
Atlassian Crowd XML External Entity Information Disclosure Vulnerability
| Bugtraq ID: | 60899 |
| Class: | Design Error |
| CVE: |
CVE-2013-3925 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2013 12:00AM |
| Updated: | Jul 02 2013 12:00AM |
| Credit: | Command Five |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Atlassian Crowd XML External Entity Information Disclosure Vulnerability
Atlassian Crowd is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks. This issue can also be exploited to send HTTP requests to intranet servers.
This issue is fixed in Atlassian Crowd versions 2.5.4, 2.6.3 and 2.7.
Atlassian Crowd is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks. This issue can also be exploited to send HTTP requests to intranet servers.
This issue is fixed in Atlassian Crowd versions 2.5.4, 2.6.3 and 2.7.
Solution / Fix
Atlassian Crowd XML External Entity Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Atlassian Crowd XML External Entity Information Disclosure Vulnerability
References:
References: