Release date:
Updated on:
Affected Systems:
Atlassian Tempo 6.4.3
Atlassian JIRA 5.0 0
Atlassian Gliffy 3.7.0
Unaffected system:
Atlassian Tempo 7.0.3 0
Atlassian Tempo 6.5.1 0
Atlassian Tempo 6.4.3.1 0
Atlassian JIRA 5.0.1 0
Atlassian Gliffy 3.7.1 0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53595
Cve id: CVE-2012-2926
Atlassian Crowd is a software for centralized identity management.
Ins such as Atlassian JIRA, Gliffy, and Tempo have a denial of service vulnerability when processing XML data. After successful exploitation, remote attackers can be allowed to cause a denial of service.
<* Source: vendor
Link: http://www.metasploit.com/modules/auxiliary/scanner/http/atlassian_crowd_fileaccess
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Atlassian
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Www.atlassian.com