CVE-2017-18110

MEDIUM

Atlassian Crowd < 3.0.2 and 3.1.0 - XML External Entity Injection via Backup Restore

Title source: llm
STIX 2.1

Description

The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/CWD-5070

Scores

CVSS v3 6.5
EPSS 0.0017
EPSS Percentile 37.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (2)
atlassian/crowd 3.1.0
atlassian/crowd < 3.0.2
Published Mar 29, 2019
Tracked Since Feb 18, 2026