#VU42759 Input validation error in Crowd Server - CVE-2013-3925

 

#VU42759 Input validation error in Crowd Server - CVE-2013-3925

Published: July 2, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42759
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2013-3925
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Crowd Server
Software vendor:
Atlassian

Description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.


Remediation

Install update from vendor's website.

External links