-
Bug
-
Resolution: Fixed
-
Medium
-
None
-
None
-
Severity 2 - Major
-
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.
[CWD-5070] The administration backup restore resource was vulnerable to XXE - CVE-2017-18110
Workflow | Original: Simplified Crowd Development Workflow v2 - restricted [ 2642982 ] | New: JAC Bug Workflow v3 [ 3365680 ] |
Summary | Original: The administration backup restore resource was vulnerable to XXE | New: The administration backup restore resource was vulnerable to XXE - CVE-2017-18110 |
Labels | Original: advisory advisory-released bugbounty cvss-medium injection security xxe | New: CVE-2017-18110 advisory advisory-released bugbounty cvss-medium injection security xxe |
Description | Original: The administration backup restore resource in Atlassian Crowd before version 3.0.2 allows remote attackers to read files from the filesystem via a XXE vulnerability. | New: The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability. |
Symptom Severity | Original: Major [ 14431 ] | New: Severity 2 - Major [ 15831 ] |
Priority | Original: Low [ 4 ] | New: Medium [ 3 ] |
Labels | Original: advisory advisory-to-release breaches-security-sla bugbounty cvss-medium injection security xxe | New: advisory advisory-released bugbounty cvss-medium injection security xxe |
Security | Original: Atlassian Staff [ 10750 ] |
Due Date | New: 03/May/2018 |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Open [ 1 ] | New: Closed [ 6 ] |