Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.103490
Category:Web application abuses
Title:Atlassian JIRA FishEye and Crucible Plugins XML Parsing Unspecified Security Vulnerability
Summary:The FishEye and Crucible plugins for JIRA are prone to an;unspecified security vulnerability because they fail to properly;handle crafted XML data.;;Exploiting this issue allows remote attackers to cause denial-of-;service conditions or to disclose local sensitive files in the context;of an affected application.;;FishEye and Crucible versions up to and including 2.7.11 are;vulnerable.
Description:Summary:
The FishEye and Crucible plugins for JIRA are prone to an
unspecified security vulnerability because they fail to properly
handle crafted XML data.

Exploiting this issue allows remote attackers to cause denial-of-
service conditions or to disclose local sensitive files in the context
of an affected application.

FishEye and Crucible versions up to and including 2.7.11 are
vulnerable.

Solution:
Updates are available. Please see the references for more information.

CVSS Score:
8.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:C

CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.