CVE-2013-3925 Information
Feb 14, 2021
cve
Description
Atlassian Crowd 2.5.x before 2.5.4 2.6.x before 2.6.3 2.3.8 and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.
Reference
http://www.commandfive.com/papers/C5_TA_2013_3925_AtlassianCrowd.pdf https://jira.atlassian.com/browse/CWD-3366
Share on: