CVE-2013-3925: Atlassian Crowd

Medium severity, CVSS 5.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.

Affected products

  • Atlassian Crowd: version 2.5.0 only; version 2.5.1 only; version 2.5.2 only; version 2.5.3 only; version 2.6.0 only; version 2.6.1 only; …

Published 2013-07-01. Last modified 2026-06-16.