CVE-2022-43782
17.11.2022, 00:15
Affected versions of Atlassian Crowd allow an attacker to authenticate as thecrowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}}path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3Enginsight
Vendor | Product | Version |
---|---|---|
atlassian | crowd | 3.0.0 ≤ 𝑥 < 4.4.4 |
atlassian | crowd | 5.0.0 ≤ 𝑥 < 5.0.3 |
𝑥
= Vulnerable software versions