Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多个Atlassian 产品权限许可和访问控制问题漏洞
Vulnerability Description
多个Atlassian产品中存在漏洞,该漏洞源于未正确限制第三方XML解析器的能力。远程攻击者可利用该漏洞借助未明向量读取任意文件,或导致拒绝服务(资源耗尽)。以下产品存在该漏洞:Atlassian JIRA 5.0.1之前版本,Confluence 3.5.16之前版本、4.0.7之前的4.0版本、4.1.10之前的4.1版本,FishEye和Crucible 2.5.8之前版本、2.6.8之前的2.6版本、2.7.12之前的2.7版本,Bamboo 3.3.4之前版本和3.4.5之前的3.4.X版本,
CVSS Information
N/A
Vulnerability Type
N/A