AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-20233

MEDIUM · CVSS 6.5 EPSS 1.82%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-18 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2018-20233
Severity
MEDIUM
CVSS
6.5
EPSS
1.82%

Original Filing — NVD Description

The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR.