Input validation error in Crowd Server - CVE-2013-3925

 

Input validation error in Crowd Server - CVE-2013-3925

Published: July 2, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42759
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2013-3925
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Atlassian
Affected software:
Crowd Server

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.


How to mitigate CVE-2013-3925

Install update from vendor's website.

Sources