Skip to main content

Vendor/product archive

atlassian / crowd CVEs

Beta · best-effort

24 CVEs tagged to atlassian / crowd5 Critical, 10 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2026-21569

Published Jan 28, 2026

This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection)…

CVSS 7.9 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2023-22521

Published Nov 21, 2023

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crowd Data Center and Server. This RCE (Remote Code Execution) vulnerability, wi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43782

Published Nov 17, 2022

Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints i…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-26137

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2022-26136

Published Jul 20, 2022

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2020-36240

Published Mar 1, 2021

The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WE…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20902

Published Oct 1, 2020

Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20104

Published Feb 6, 2020

The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18107

Published Dec 17, 2019

Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site req…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11580

Published Jun 3, 2019

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests…

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
68.7
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-18110

Published Mar 29, 2019

The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the files…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18109

Published Mar 29, 2019

The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18108

Published Mar 29, 2019

The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI inj…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18106

Published Mar 29, 2019

The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18105

Published Mar 29, 2019

The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESS…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20238

Published Feb 13, 2019

Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10740

Published Jan 29, 2019

Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16858

Published Jan 31, 2018

The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crow…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6496

Published Dec 9, 2016

The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serializ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3926

Published Jul 1, 2013

Atlassian Crowd 2.6.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to a "symmetric backdoor." NOTE: as of 20130704, the vendor could not…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-3925

Published Jul 1, 2013

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request t…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1