cbcvebase.
CVE-2012-2928
published 2012-05-22

CVE-2012-2928: The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML…

PriorityP431medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
3.06%
86.2th percentile
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
atlassianconfluence_server
atlassianjira<= 5.0.0
gliffygliffy<= 3.7
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.