CVE-2012-2928: Medium severity Gliffy Gliffy vulnerability
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2928?
CVE-2012-2928 is considered to be a medium severity vulnerability due to its potential to allow remote attackers to read arbitrary files or consume resources.
How do I fix CVE-2012-2928?
To fix CVE-2012-2928, upgrade to Gliffy plugin version 3.7.1 or later for Atlassian JIRA and 4.2 or later for Atlassian Confluence.
What systems are affected by CVE-2012-2928?
CVE-2012-2928 affects Gliffy plugin versions up to 3.7 and Atlassian JIRA versions up to 5.0.0 along with specific versions of Atlassian Confluence.
What are the potential consequences of CVE-2012-2928?
The consequences of CVE-2012-2928 could include unauthorized access to sensitive files and denial of service through resource exhaustion.
How can I determine if I am vulnerable to CVE-2012-2928?
You can determine your vulnerability to CVE-2012-2928 by checking the version of the Gliffy plugin and Atlassian applications you are running.