Uploaded image for project: 'Confluence Server'
  1. Confluence Server
  2. CONFSERVER-25077

XML Vulnerability in Confluence

    XMLWordPrintable

    Details

      Description

      We have identified and fixed a vulnerability in Confluence that results from the way third-party XML parsers are used in Confluence. This vulnerability allows an attacker to:

      • Execute denial of service attacks against the Confluence server, or
      • Read all local files readable to the system user under which Confluence runs.

      The attacker does not need to have an account with the affected Confluence instance.

      All versions of Confluence up to and including 4.1.9 are affected.

      Full details of the severity, risks and vulnerability can be found in the Confluence Security Advisory 2012-05-17.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              vosipov Vitaly Osipov [Atlassian]
              Reporter:
              alui Andrew Lui
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: