CVE-2012-2928
published 2012-05-22CVE-2012-2928: The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML…
PriorityP431medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
3.06%
86.2th percentile
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_server | — | — |
| atlassian | jira | <= 5.0.0 | — |
| gliffy | gliffy | <= 3.7 | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
| gliffy | gliffy | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://confluence.atlassian.com/display/DOC/Confluence+Security+Advisory+2012-05-17http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2012-05-17http://osvdb.org/81993http://secunia.com/advisories/49166http://www.securityfocus.com/bid/53595https://exchange.xforce.ibmcloud.com/vulnerabilities/75697http://confluence.atlassian.com/display/DOC/Confluence+Security+Advisory+2012-05-17http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2012-05-17http://osvdb.org/81993http://secunia.com/advisories/49166http://www.securityfocus.com/bid/53595https://exchange.xforce.ibmcloud.com/vulnerabilities/75697
2012-05-22
Published