Uploaded image for project: 'Project Configurator - Development'
  1. Project Configurator - Development
  2. PCDEV-1331

XXE vulnerability when reading XML files

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Done
    • Highest
    • Resolution: Fixed
    • 3.0.8
    • 3.0.9
    • None
    • PC Sprint 19 BUGS & SR
    • 0

    Description

      Severity: Medium

      Jira System Administrators were able read files and network resources (such as http) accessible to the Jira server via an XML external entity (XXE) flaw.

      This issue affects all versions of Project Configurator prior to 3.0.9

      This has been fixed in Project Configurator version 3.0.9. Please upgrade to version 3.0.9 or later.

       

      Attachments

        Issue Links

          Activity

            People

              pmaranon Pepe Maranon Mora
              pmaranon Pepe Maranon Mora
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: