Vulnerabilities (CVE)

Filtered by vendor Gliffy Subscribe
Filtered by product Gliffy
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-2928 2 Atlassian, Gliffy 3 Confluence Server, Jira, Gliffy 2023-12-10 6.4 MEDIUM N/A
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.