Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-2928

EPSS 1.93% · P84
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-2928

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Atlassian JIRA/Confluence ‘Gliffy’ 插件拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
JIRA是澳大利亚Atlassian公司开发的一款不错的商业问题跟踪工具,可以对各种类型的问题进行跟踪管理,包括缺陷、需求变更、评审记录等。 Atlassian JIRA的Gliffy插件3.7.1之前版本与Atlassian Confluence的4.2之前版本中存在漏洞,该漏洞源于未正确限制第三方XML解析器的能力。远程攻击者可利用该漏洞借助未明向量读取任意文件,或者导致拒绝服务(资源消耗)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-2928

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-2928

登录查看更多情报信息。

Same Patch Batch · n/a · 2012-05-22 · 7 CVEs total

CVE-2012-1990Schneider Electric Kerweb/Kerwin多个跨站脚本漏洞
CVE-2012-2759WordPress ‘Login With Ajax’ 插件跨站脚本漏洞
CVE-2012-2926多个Atlassian 产品权限许可和访问控制问题漏洞
CVE-2012-2562Xelex MobileTrack输入验证漏洞
CVE-2012-2567Xelex MobileTrack敏感信息泄露漏洞
CVE-2012-2927Atlassian JIRA ‘TM Software Tempo’ 插件拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2012-2928

No comments yet


Leave a comment