CVE-2022-43782
published 2022-11-17CVE-2022-43782: Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.89%
55.1th percentile
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path.
This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default.
The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | crowd | >= 3.0.0 < 4.4.4 | 4.4.4 |
| atlassian | crowd | >= 5.0.0 < 5.0.3 | 5.0.3 |
| atlassian | crowd_data_center | — | — |
| atlassian | crowd_data_center | — | — |
| atlassian | crowd_server | — | — |
| atlassian | crowd_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the privileged REST API path `/usermanagement` — exploitation involves calling privileged endpoints under this path after authenticating as the crowd application ↗
- →Exploitation is only possible from IPs present in the Crowd application's Remote Addresses allowlist; monitor for unexpected IPs added to this allowlist, or for REST API calls to `/usermanagement` from IPs not normally associated with legitimate Crowd integrations ↗
- ·Exploitation requires the attacker's IP to be present in the Crowd application's Remote Addresses allowlist. The default value is 'none', meaning no IPs are allowed by default — the attack surface only opens if this list has been populated. ↗
- ·Affected versions are all 3.x.x, 4.x.x before 4.4.4, and 5.x.x before 5.0.3. Instances already on 4.4.4+ or 5.0.3+ are not vulnerable. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2022-11-17
Published