Input validation error in Crowd Server - CVE-2013-3925

 

Input validation error in Crowd Server - CVE-2013-3925

Published: July 2, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42759
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-3925
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.


Affected software

Crowd Server

How to mitigate CVE-2013-3925

Install update from vendor's website.


External References

Related Security Bulletins