Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2013-07-01 14:55
Updated : 2013-07-01 21:00
NVD link : CVE-2013-3925
Mitre link : CVE-2013-3925
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
atlassian
- crowd