CVE-2017-18110: XEE
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-18110.
What is the title of this vulnerability?
The title of this vulnerability is 'The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.'
What is the severity of CVE-2017-18110?
The severity of CVE-2017-18110 is medium.
What software versions are affected by CVE-2017-18110?
Atlassian Crowd versions before 3.0.2 and from 3.1.0 to 3.1.1 are affected by CVE-2017-18110.
How can an attacker exploit CVE-2017-18110?
Remote attackers can exploit CVE-2017-18110 to read files from the filesystem via a XXE vulnerability.