← Back

CVE-2012-2926

nvd nist
Published: May 22, 2012Modified: Apr 29, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.

Affected (17)

7 products
Bamboo
Confluence
Confluence Server
Crowd
Crucible
Fisheye
Jira
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Atlassian
Before 3.3.4
From 3.4 to 3.4.5
Before 3.5.16
Atlassian
From 4.0 to 4.0.7
From 4.1 to 4.1.10
Atlassian
Before 2.0.9
From 2.1 to 2.1.2
From 2.2.0 to 2.2.9
From 2.3.0 to 2.3.7
From 2.4.0 to 2.4.1
Atlassian
Before 2.5.8
From 2.6 to 2.6.8
From 2.7 to 2.7.12
Atlassian
Before 2.5.8
From 2.6 to 2.6.8
From 2.7 to 2.7.12
Before 5.0.1

References (20)

Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Not Applicable
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.