Beveiligingsadvies

CVE-2013-3925

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2013-07-01 21:00:00
Laatst bijgewerkt 2024-09-16 19:37:09
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.