First published: Fri Mar 29 2019(Updated: )
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Crowd | <3.0.2 | |
Atlassian Crowd | =3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-18110.
The title of this vulnerability is 'The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.'
The severity of CVE-2017-18110 is medium.
Atlassian Crowd versions before 3.0.2 and from 3.1.0 to 3.1.1 are affected by CVE-2017-18110.
Remote attackers can exploit CVE-2017-18110 to read files from the filesystem via a XXE vulnerability.