Atlassian Crowd contains a flaw that may allow a remote information disclosure. The issue is triggered when an unspecified error occurs in any one of multiple XML parsers, and will grant an attacker access to arbitrary files.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service,
Information Disclosure
Impact:
Loss of Confidentiality,
Loss of Availability
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
Upgrade to version 2.0.9, 2.1.2, 2.2.9, 2.3.7 or 2.4.1 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.