CVE-2018-20233: Atlassian Universal Plugin Manager
Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR.
Affected products
- Atlassian Universal Plugin Manager: before 2.22.14 (fixed in 2.22.14)
Published 2019-01-18. Last modified 2026-06-17.