CVE-2019-20902
01.10.2020, 02:15
Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.Enginsight
Vendor | Product | Version |
---|---|---|
atlassian | crowd | 𝑥 < 3.4.6 |
atlassian | crowd | 3.5.0 ≤ 𝑥 < 3.5.1 |
𝑥
= Vulnerable software versions