Description
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-12799 | The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR. |
References
History
No history.
Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2024-09-16T22:09:10.800Z
Reserved: 2018-12-19T00:00:00.000Z
Link: CVE-2018-20233
No data.
Status : Modified
Published: 2019-01-18T21:29:00.197
Modified: 2024-11-21T04:01:08.173
Link: CVE-2018-20233
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD