Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-18111

Опубликовано: 29 мар. 2019
Источник: nvd
CVSS3: 8.7
CVSS2: 5.5
EPSS Низкий

Описание

The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when consuming a client OAuth request. This allowed malicious oauth application linked applications to probe internal network resources by requesting internal locations, read the contents of files and also cause an out of memory exception affecting availability via an XML External Entity vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:atlassian:application_links:*:*:*:*:*:*:*:*
Версия до 5.0.10 (исключая)
cpe:2.3:a:atlassian:application_links:*:*:*:*:*:*:*:*
Версия от 5.1.0 (включая) до 5.1.3 (исключая)
cpe:2.3:a:atlassian:application_links:*:*:*:*:*:*:*:*
Версия от 5.2.0 (включая) до 5.2.6 (исключая)

EPSS

Процентиль: 34%
0.0014
Низкий

8.7 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.7
github
больше 3 лет назад

The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when consuming a client OAuth request. This allowed malicious oauth application linked applications to probe internal network resources by requesting internal locations, read the contents of files and also cause an out of memory exception affecting availability via an XML External Entity vulnerability.

EPSS

Процентиль: 34%
0.0014
Низкий

8.7 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-611