CVE-2013-3926Atlassian Crowd vulnerability

3 documents3 sources
Severity
7.5HIGHNVD
EPSS
1.0%
top 22.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 1
Latest updateMay 17

Description

Atlassian Crowd 2.6.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to a "symmetric backdoor." NOTE: as of 20130704, the vendor could not reproduce the issue, stating "We've been unable to substantiate the existence of [CVE-2013-3926]. The author of the article has not contacted Atlassian and has provided no detail, making it difficult to validate the claim... If we can confirm that there is a vulnerability, a patch will be issued.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDatlassian/crowd2.6.3

🔴Vulnerability Details

2
GHSA
GHSA-9fh4-qmm7-wrrj: ** DISPUTED ** Atlassian Crowd 22022-05-17
CVEList
CVE-2013-3926: Atlassian Crowd 22013-07-01
CVE-2013-3926 — Atlassian Crowd vulnerability | cvebase