CVE-2012-2928
Published May 22, 2012
Last updated 3 years ago
Overview
- Description
- The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gliffy:gliffy:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "704F51BA-F57D-472A-8EE1-C379707862D1", "versionEndIncluding": "3.7" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "070964FD-C020-4FE3-8CCA-636BFA61097C", "versionEndIncluding": "5.0.0" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gliffy:gliffy:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "704F51BA-F57D-472A-8EE1-C379707862D1", "versionEndIncluding": "3.7" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7ED8E5BF-B56C-41DE-9D69-E162A5E3583D" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C454A6FA-38A6-4D7C-BF0B-11AF44A149DD" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "628EF8B6-C02C-4E29-B211-A0BE32E07A02" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "502FC1F6-DAD8-43D7-8284-FA069043BB1F" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "116447B6-9A17-4CB0-8A09-217E0091E455" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:2.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "426AA696-27C6-4F96-95E8-A321846EBBA8" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:2.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8592BF3C-4775-412D-9EAE-F9E9383E266A" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:2.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA4EE594-46BB-4776-B59D-188D4A9A2FB2" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B50AA29-33EA-4F80-828F-DCF78FEE96B6" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:2.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "497CA254-4BAA-439C-BF86-0F2EE436C446" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7E1978F-8C30-4253-9086-D439FCFCEC86" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A31ADDF1-50C9-49B2-B4DF-9AF105CD0D31" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B76A0BC1-7992-46A9-A840-6A35EB8EB465" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9B9559A-0EA1-4D5B-9192-51920E38C42B" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8113F2E-24C7-4885-B15B-5348E1EF6544" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F72A3B15-5609-4A4F-A22C-196D9E627CE0" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35AF35E4-4E1E-4541-B21C-92E7D25D97E3" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "889DEB85-F871-42B5-8D4E-C523012166DC" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36E8862D-C197-409D-9267-421443C818A8" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A94733F8-8546-4A65-BD1E-AC4E96FFA72B" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "346A151B-0325-4147-B447-D6714B0DA9AB" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6DDC9C9-E46A-4938-8A84-BF3C2B599753" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A32FE9D-3DD1-45A3-A4DA-B139FC4C9E16" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19C3CD54-D9E6-4728-89BD-DD7B24999B39" }, { "criteria": "cpe:2.3:a:gliffy:gliffy:3.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "988E035E-3DCA-4FBF-BDBF-73E3E76B6ED2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atlassian:confluence_server:4.1.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5AE43247-03FB-47DE-B1AE-0B269CAFE973" } ], "operator": "OR" } ], "operator": "AND" } ]