The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/49166 | third party advisory vendor advisory |
http://confluence.atlassian.com/display/DOC/Confluence+Security+Advisory+2012-05-17 | mitigation vendor advisory |
http://osvdb.org/81993 | vdb entry broken link |
http://www.securityfocus.com/bid/53595 | broken link third party advisory vdb entry |
http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2012-05-17 | mitigation vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/75697 | third party advisory vdb entry |