cbcvebase.
CVE-2012-2928
published 2012-05-22

CVE-2012-2928: The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML…

medium6.4CVSS 3.1
AVNACLAuNCPINAP
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
atlassianconfluence_server
atlassianjira<= 5.0.0
gliffygliffy<= 3.7
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy
gliffygliffy