Atlassian

Crowd

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.86%
  • Veröffentlicht 21.11.2023 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:44:58

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crowd Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.0, allows an authenticated attacker to execute arb...

  • EPSS 0.57%
  • Veröffentlicht 17.11.2022 00:15:18
  • Zuletzt bearbeitet 21.11.2024 07:27:14

Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerabili...

  • EPSS 0.07%
  • Veröffentlicht 20.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security...

  • EPSS 0.28%
  • Veröffentlicht 20.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulner...

  • EPSS 0.35%
  • Veröffentlicht 01.03.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:07

The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

  • EPSS 0.3%
  • Veröffentlicht 01.10.2020 02:15:12
  • Zuletzt bearbeitet 21.11.2024 04:39:39

Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.

Exploit
  • EPSS 2.43%
  • Veröffentlicht 06.02.2020 03:15:10
  • Zuletzt bearbeitet 21.11.2024 04:38:04

The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.

  • EPSS 0.41%
  • Veröffentlicht 17.12.2019 04:15:10
  • Zuletzt bearbeitet 21.11.2024 03:19:22

Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo applic...

  • EPSS 0.21%
  • Veröffentlicht 08.11.2019 04:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:51

The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message m...

Warnung Exploit
  • EPSS 94.41%
  • Veröffentlicht 03.06.2019 14:29:00
  • Zuletzt bearbeitet 24.10.2025 13:39:10

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerabilit...