Lucene search

K
atlassianDblackCWD-4355
HistoryMay 12, 2015 - 7:34 a.m.

Update the version of commons-httpclient to address CVE-2012-5783 & CVE-2014-3577 and gain SNI support

2015-05-1207:34:43
dblack
jira.atlassian.com
24

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.004 Low

EPSS

Percentile

74.9%

Upgrade commons-httpclient to version {{3.1-atlassian-2}} to gain SNI support and to fix CVE-2012-5783 & CVE-2014-3577.

Affected configurations

Vulners
Node
atlassiancrowdRange2.8.2
OR
atlassiancrowdRange<2.8.3

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.004 Low

EPSS

Percentile

74.9%