Atlassian Crowd Data Center vulnerabilities
5 known vulnerabilities affecting atlassian/crowd_data_center.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3
Vulnerabilities
Page 1 of 1
CVE-2026-21569HIGHCVSS 7.9v7.1.0 to 7.1.22026-01-28
CVE-2026-21569 [HIGH] CWE-611 CVE-2026-21569: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0
This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server.
This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, h
cvelistv5nvd
CVE-2023-22521HIGHCVSS 8.8v>= 3.4.6v>= 5.2.02023-11-21
CVE-2023-22521 [HIGH] CVE-2023-22521: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crow
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crowd Data Center and Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.0, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and
cvelistv5nvd
CVE-2022-43782CRITICALCVSS 9.8vbefore 4.4.4vbefore 5.0.32022-11-17
CVE-2022-43782 [CRITICAL] CVE-2022-43782: Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path.
This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses conf
cvelistv5nvd
CVE-2022-26136CRITICALCVSS 9.8≥ unspecified, < 4.3.8≥ 4.4.0, < unspecified+2 more2022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
cvelistv5nvd
CVE-2022-26137HIGHCVSS 8.8≥ unspecified, < 4.3.8≥ 4.4.0, < unspecified+2 more2022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
cvelistv5nvd