Release date: 2013-07-02
Updated on: 2013-07-04
Affected Systems:
Atlassian Crowd 2.6.2
Atlassian Crowd 2.5.3
Atlassian Crowd 2.4.9
Atlassian Crowd 2.3.8
Atlassian Crowd
Description:
--------------------------------------------------------------------------------
Bugtraq id: 60899
CVE (CAN) ID: CVE-2013-3925
Atlassian Crowd is a software for centralized identity management.
Atlassian Crowd 2.5.x, 2.6.x, 2.3.8, and 2.4.9 have security vulnerabilities. Remote attackers can exploit this vulnerability to read arbitrary files and request/services/2 or services/latest, the requested DTD contains the XML external entity declaration associated with the object index, and sends an HTTP request to the internal server.
<* Source: Command Five
Link: https://jira.atlassian.com/browse/CWD-3366
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Atlassian
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Www.atlassian.com