// For flags

CVE-2012-2928

 

Severity Score

6.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.

El complemento Gliffy para Atlassian JIRA v3.7.1, y en version anteriores ala v4.2 para Atlassian Confluence, no restringe correctamente las capacidades de los analizadores XML de tercer nivel, lo que permite leer ficheros de su elección o causar una denegación de servicio (por excesivo consumo de recursos) a atacantes remotos a través de vectores no especificados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-05-22 CVE Reserved
  • 2012-05-22 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Atlassian
Search vendor "Atlassian"
Jira
Search vendor "Atlassian" for product "Jira"
<= 5.0.0
Search vendor "Atlassian" for product "Jira" and version " <= 5.0.0"
-
Affected
in Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
<= 3.7
Search vendor "Gliffy" for product "Gliffy" and version " <= 3.7"
-
Safe
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
<= 3.7
Search vendor "Gliffy" for product "Gliffy" and version " <= 3.7"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
1.0.1
Search vendor "Gliffy" for product "Gliffy" and version "1.0.1"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
2.0.0
Search vendor "Gliffy" for product "Gliffy" and version "2.0.0"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
2.0.1
Search vendor "Gliffy" for product "Gliffy" and version "2.0.1"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
2.1.0
Search vendor "Gliffy" for product "Gliffy" and version "2.1.0"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
2.1.1
Search vendor "Gliffy" for product "Gliffy" and version "2.1.1"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
2.1.2
Search vendor "Gliffy" for product "Gliffy" and version "2.1.2"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
2.1.3
Search vendor "Gliffy" for product "Gliffy" and version "2.1.3"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
2.2.0
Search vendor "Gliffy" for product "Gliffy" and version "2.2.0"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
2.2.1
Search vendor "Gliffy" for product "Gliffy" and version "2.2.1"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
2.2.2
Search vendor "Gliffy" for product "Gliffy" and version "2.2.2"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.0.0
Search vendor "Gliffy" for product "Gliffy" and version "3.0.0"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.0.1
Search vendor "Gliffy" for product "Gliffy" and version "3.0.1"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.0.2
Search vendor "Gliffy" for product "Gliffy" and version "3.0.2"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.0.3
Search vendor "Gliffy" for product "Gliffy" and version "3.0.3"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.0.4
Search vendor "Gliffy" for product "Gliffy" and version "3.0.4"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.0.5
Search vendor "Gliffy" for product "Gliffy" and version "3.0.5"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.1.0
Search vendor "Gliffy" for product "Gliffy" and version "3.1.0"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.1.1
Search vendor "Gliffy" for product "Gliffy" and version "3.1.1"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.1.2
Search vendor "Gliffy" for product "Gliffy" and version "3.1.2"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.1.3
Search vendor "Gliffy" for product "Gliffy" and version "3.1.3"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.1.4
Search vendor "Gliffy" for product "Gliffy" and version "3.1.4"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.5
Search vendor "Gliffy" for product "Gliffy" and version "3.5"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.5.2
Search vendor "Gliffy" for product "Gliffy" and version "3.5.2"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.6
Search vendor "Gliffy" for product "Gliffy" and version "3.6"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected
Gliffy
Search vendor "Gliffy"
Gliffy
Search vendor "Gliffy" for product "Gliffy"
3.6.1
Search vendor "Gliffy" for product "Gliffy" and version "3.6.1"
-
Affected
in Atlassian
Search vendor "Atlassian"
Confluence Server
Search vendor "Atlassian" for product "Confluence Server"
4.1.9
Search vendor "Atlassian" for product "Confluence Server" and version "4.1.9"
-
Affected