cbcvebase.

Atlassian Crowd vulnerabilities

24 known vulnerabilities affecting atlassian/crowd.

Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH10MEDIUM9

Vulnerabilities

Page 2 of 2
CVE-2017-18107P4MEDIUMCVSS 6.5fixed in 3.1.1≥ unspecified, < 3.1.12019-12-17
CVE-2017-18107 [MEDIUM] CWE-352 CVE-2017-18107: Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default.
nvd
CVE-2016-10740P4MEDIUMCVSS 4.9fixed in 2.10.12019-01-29
CVE-2016-10740 [MEDIUM] CWE-200 CVE-2016-10740: Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administratio Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources.
nvd
CVE-2017-18109P4MEDIUMCVSS 6.1fixed in 3.0.2v3.1.0+3 more2019-03-29
CVE-2017-18109 [MEDIUM] CWE-601 CVE-2017-18109: The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
nvd
CVE-2019-15005P4MEDIUMCVSS 4.3fixed in 3.6.0≥ unspecified, < 3.6.02019-11-08
CVE-2019-15005 [MEDIUM] CWE-862 CVE-2019-15005: The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivilege The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulne
nvd