We have identified and fixed a vulnerability in JIRA that results from the way third-party XML parsers are used in JIRA. This vulnerability allows an attacker who is an authenticated JIRA user to execute denial of service attacks against the JIRA server.

      All versions of JIRA up to and including 5.0.0 are affected.

      Full details of the severity, risks and vulnerability can be found in the JIRA Security Advisory 2012-05-17.

            [JRASERVER-27719] XML Vulnerability in JIRA

            Rachel Robins made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 102379 ]
            Bugfix Automation Bot made changes -
            Minimum Version New: 5
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2843657 ] New: JAC Bug Workflow v3 [ 2912236 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2579492 ] New: JAC Bug Workflow v2 [ 2843657 ]
            Ignat (Inactive) made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v6 - Restricted [ 1543011 ] New: JIRA Bug Workflow w Kanban v7 - Restricted [ 2579492 ]
            Confluence Escalation Bot (Inactive) made changes -
            Labels Original: advisory cvss-high security New: advisory affects-server cvss-high security
            Oswaldo Hernandez (Inactive) made changes -
            Component/s Original: Security [Deprecated] [ 11831 ]
            Oswaldo Hernandez (Inactive) made changes -
            Status Original: Closed [ 6 ] New: Resolved [ 5 ]
            Owen made changes -
            Workflow Original: JIRA Bug Workflow w Kanban v6 [ 666449 ] New: JIRA Bug Workflow w Kanban v6 - Restricted [ 1543011 ]
            Tony Starr made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 17400 ] New: This issue links to "Page (Atlassian Documentation)" [ 17400 ]

              vosipov VitalyA
              alui Andrew
              Affected customers:
              0 This affects my team
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: