CVE-2013-3925
Published Jul 1, 2013
Last updated 9 months ago
Overview
- Description
- Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atlassian:crowd:2.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99E8058A-FACB-41B7-982F-E97C513EB814" }, { "criteria": "cpe:2.3:a:atlassian:crowd:2.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13F2E20D-A958-4BA2-BD6A-C802B99CC57A" }, { "criteria": "cpe:2.3:a:atlassian:crowd:2.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D63E6CB9-266C-4348-AB2E-BDF568FA86D0" }, { "criteria": "cpe:2.3:a:atlassian:crowd:2.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "75DC949F-E218-4142-AAB5-AF932E9C93D6" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atlassian:crowd:2.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99582FB9-DE06-40F6-9E19-9EBF10DD8A47" }, { "criteria": "cpe:2.3:a:atlassian:crowd:2.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "479873F5-3B68-44E3-989B-E714E531ADF7" }, { "criteria": "cpe:2.3:a:atlassian:crowd:2.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE29ECF3-D6E8-43E4-94F8-C6564B1BAF9F" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atlassian:crowd:2.3.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3DBE57E2-9F40-400A-B476-2D3243843489" }, { "criteria": "cpe:2.3:a:atlassian:crowd:2.4.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "851C6C41-5BB8-4C8F-B268-68DF6C808AB8" } ], "operator": "OR" } ] } ]