-
Bug
-
Resolution: Fixed
-
Medium
-
None
-
None
-
Severity 2 - Major
-
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 6.8 => Medium severity
Exploitability Metrics
Scope Metric
Impact Metrics