VYPR
Medium severity6.5NVD Advisory· Published Jan 18, 2019· Updated Jun 17, 2026

CVE-2018-20233

CVE-2018-20233

Description

The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR.

Affected products

3
  • cpe:2.3:a:atlassian:universal_plugin_manager:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:atlassian:universal_plugin_manager:*:*:*:*:*:*:*:*range: <2.22.14
    • (no CPE)range: <2.22.14
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.