Search

Find a vulnerability

Search criteria

    16 vulnerabilities found for crowd by atlassian

    CVE-2022-43782 (GCVE-0-2022-43782)

    Vulnerability from cvelistv5 – Published: 2022-11-17 00:00 – Updated: 2024-10-02 15:05
    VLAI
    Summary
    Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-02 15:01 UTC
    CWE
    • Security Misconfiguration
    References
    Impacted products
    Vendor Product Version
    Atlassian Crowd Data Center Unaffected: before 3.0.0
    Affected: before 4.4.4
    Affected: before 5.0.3
    Create a notification for this product.
    Atlassian Crowd Server Unaffected: before 3.0.0
    Affected: before 4.4.4
    Affected: before 5.0.3
    Create a notification for this product.
    atlassian crowd Affected: 3.0.0 , < 4.4.4 (custom)
    Affected: 5.0.0 , < 5.0.3 (custom)
        cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T13:40:06.314Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5888"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crowd",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.4.4",
                    "status": "affected",
                    "version": "3.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "5.0.3",
                    "status": "affected",
                    "version": "5.0.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-43782",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-02T15:01:35.451793Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-02T15:05:47.174Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "before 3.0.0"
                },
                {
                  "status": "affected",
                  "version": "before 4.4.4"
                },
                {
                  "status": "affected",
                  "version": "before 5.0.3"
                }
              ]
            },
            {
              "product": "Crowd Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "before 3.0.0"
                },
                {
                  "status": "affected",
                  "version": "before 4.4.4"
                },
                {
                  "status": "affected",
                  "version": "before 5.0.3"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Ashish Kotha"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Affected versions of Atlassian Crowd allow an attacker to authenticate as the\u00a0crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd\u0027s REST API under the {{usermanagement}}\u00a0path.\n\nThis vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default.\n\nThe affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Misconfiguration",
                  "lang": "en",
                  "type": "Security Misconfiguration"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-11-17T00:00:01.315Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://jira.atlassian.com/browse/CWD-5888"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2022-43782",
        "datePublished": "2022-11-17T00:00:01.315Z",
        "dateReserved": "2022-10-26T14:49:11.115Z",
        "dateUpdated": "2024-10-02T15:05:47.174Z",
        "requesterUserId": "4ceb4895-2afc-4c29-bf72-c2e04b367c52",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-26137 (GCVE-0-2022-26137)

    Vulnerability from cvelistv5 – Published: 2022-07-20 17:25 – Updated: 2024-10-03 17:10
    VLAI
    Summary
    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-03 16:48 UTC
    CWE
    • CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize (CWE-180)
    Impacted products
    Vendor Product Version
    Atlassian Bamboo Server Affected: unspecified , < 8.0.9 (custom)
    Affected: 8.1.0 , < unspecified (custom)
    Affected: unspecified , < 8.1.8 (custom)
    Affected: 8.2.0 , < unspecified (custom)
    Affected: unspecified , < 8.2.4 (custom)
    Create a notification for this product.
    Atlassian Bamboo Data Center Affected: unspecified , < 8.0.9 (custom)
    Affected: 8.1.0 , < unspecified (custom)
    Affected: unspecified , < 8.1.8 (custom)
    Affected: 8.2.0 , < unspecified (custom)
    Affected: unspecified , < 8.2.4 (custom)
    Create a notification for this product.
    Atlassian Bitbucket Server Affected: unspecified , < 7.6.16 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.8 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.19.5 (custom)
    Affected: 7.20.0 , < unspecified (custom)
    Affected: unspecified , < 7.20.2 (custom)
    Affected: 7.21.0 , < unspecified (custom)
    Affected: unspecified , < 7.21.2 (custom)
    Affected: 8.0.0
    Affected: 8.1.0
    Create a notification for this product.
    Atlassian Bitbucket Data Center Affected: unspecified , < 7.6.16 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.8 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.19.5 (custom)
    Affected: 7.20.0 , < unspecified (custom)
    Affected: unspecified , < 7.20.2 (custom)
    Affected: 7.21.0 , < unspecified (custom)
    Affected: unspecified , < 7.21.2 (custom)
    Affected: 8.0.0
    Affected: 8.1.0
    Create a notification for this product.
    Atlassian Confluence Server Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0
    Create a notification for this product.
    Atlassian Confluence Data Center Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0
    Create a notification for this product.
    Atlassian Crowd Server Affected: unspecified , < 4.3.8 (custom)
    Affected: 4.4.0 , < unspecified (custom)
    Affected: unspecified , < 4.4.2 (custom)
    Affected: 5.0.0
    Create a notification for this product.
    Atlassian Crowd Data Center Affected: unspecified , < 4.3.8 (custom)
    Affected: 4.4.0 , < unspecified (custom)
    Affected: unspecified , < 4.4.2 (custom)
    Affected: 5.0.0
    Create a notification for this product.
    Atlassian Crucible Affected: unspecified , < 4.8.10 (custom)
    Create a notification for this product.
    Atlassian Fisheye Affected: unspecified , < 4.8.10 (custom)
    Create a notification for this product.
    Atlassian Jira Core Server Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Software Server Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Software Data Center Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Service Management Server Affected: unspecified , < 4.13.22 (custom)
    Affected: 4.14.0 , < unspecified (custom)
    Affected: unspecified , < 4.20.10 (custom)
    Affected: 4.21.0 , < unspecified (custom)
    Affected: unspecified , < 4.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Service Management Data Center Affected: unspecified , < 4.13.22 (custom)
    Affected: 4.14.0 , < unspecified (custom)
    Affected: unspecified , < 4.20.10 (custom)
    Affected: 4.21.0 , < unspecified (custom)
    Affected: unspecified , < 4.22.4 (custom)
    Create a notification for this product.
    atlassian bamboo Affected: 7.2.0 , < 7.2.10 (custom)
    Affected: 8.0.0 , < 8.0.9 (custom)
    Affected: 8.1.0 , < 8.1.8 (custom)
    Affected: 8.2.0 , < 8.2.4 (custom)
        cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 0 , < 7.6.16 (custom)
    Affected: 7.7.0 , < 7.17.8 (custom)
    Affected: 7.18.0 , < 7.19.5 (custom)
    Affected: 7.20.1 , < 7.20.2 (custom)
    Affected: 7.21.0 , < 7.21.2 (custom)
        cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 8.0.0
        cpe:2.3:a:atlassian:bitbucket:8.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 8.1.0
        cpe:2.3:a:atlassian:bitbucket:8.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 0 , < 7.4.17 (custom)
    Affected: 7.5.0 , < 7.13.7 (custom)
    Affected: 7.14.0 , < 7.14.3 (custom)
    Affected: 7.15.0 , < 7.15.2 (custom)
    Affected: 7.16.0 , < 7.16.4 (custom)
    Affected: 7.17.0 , < 7.17.4 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 7.18.0
        cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 0 , < 7.4.17 (custom)
    Affected: 7.5.0 , < 7.13.7 (custom)
    Affected: 7.14.0 , < 7.14.3 (custom)
    Affected: 7.15.0 , < 7.15.2 (custom)
    Affected: 7.16.0 , < 7.16.4 (custom)
    Affected: 7.17.0 , < 7.17.4 (custom)
        cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 7.18.0
        cpe:2.3:a:atlassian:confluence_server:7.18.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crowd Affected: 0 , < 4.3.8 (custom)
    Affected: 4.4.0 , < 4.4.2 (custom)
        cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crowd Affected: 5.0.0
        cpe:2.3:a:atlassian:crowd:5.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crucible Affected: 0 , < 4.8.10 (custom)
        cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian fisheye Affected: 0 , < 4.8.10 (custom)
        cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_data_center Affected: 8.13.0 , < 8.13.22 (custom)
    Affected: 8.14.0 , < 8.20.10 (custom)
    Affected: 8.21.0 , < 8.22.4 (custom)
        cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_server Affected: 8.13.0 , < 8.13.22 (custom)
    Affected: 8.14.0 , < 8.20.10 (custom)
    Affected: 8.21.0 , < 8.22.4 (custom)
        cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_service_desk Affected: 0 , < 4.13.22 (custom)
        cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:server:*:*:*
    Create a notification for this product.
    atlassian jira_service_desk Affected: 0 , < 4.13.22 (custom)
        cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:data_center:*:*:*
    Create a notification for this product.
    atlassian jira_service_management Affected: 4.14.0 , < 4.20.10 (custom)
    Affected: 4.21.0 , < 4.22.4 (custom)
        cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*
    Create a notification for this product.
    atlassian jira_service_management Affected: 4.14.0 , < 4.20.10 (custom)
    Affected: 4.21.0 , < 4.22.4 (custom)
        cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*
    Create a notification for this product.
    Date Public
    2022-07-20 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:56:37.614Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/BAM-21795"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/BSERV-13370"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5815"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/FE-7410"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CRUC-8541"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bamboo",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.2.10",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.0.9",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.1.8",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.2.4",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.6.16",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.8",
                    "status": "affected",
                    "version": "7.7.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.19.5",
                    "status": "affected",
                    "version": "7.18.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.20.2",
                    "status": "affected",
                    "version": "7.20.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.21.2",
                    "status": "affected",
                    "version": "7.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:8.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.0.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:8.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.1.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.4.17",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.13.7",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.14.3",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.15.2",
                    "status": "affected",
                    "version": "7.15.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.16.4",
                    "status": "affected",
                    "version": "7.16.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.4",
                    "status": "affected",
                    "version": "7.17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.18.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.4.17",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.13.7",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.14.3",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.15.2",
                    "status": "affected",
                    "version": "7.15.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.16.4",
                    "status": "affected",
                    "version": "7.16.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.4",
                    "status": "affected",
                    "version": "7.17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:7.18.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.18.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crowd",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.3.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.4.2",
                    "status": "affected",
                    "version": "4.4.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crowd:5.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crowd",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.0.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crucible",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.8.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fisheye",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.8.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.13.22",
                    "status": "affected",
                    "version": "8.13.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.20.10",
                    "status": "affected",
                    "version": "8.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.22.4",
                    "status": "affected",
                    "version": "8.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.13.22",
                    "status": "affected",
                    "version": "8.13.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.20.10",
                    "status": "affected",
                    "version": "8.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.22.4",
                    "status": "affected",
                    "version": "8.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:server:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_desk",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.13.22",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:data_center:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_desk",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.13.22",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_management",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.20.10",
                    "status": "affected",
                    "version": "4.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.22.4",
                    "status": "affected",
                    "version": "4.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_management",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.20.10",
                    "status": "affected",
                    "version": "4.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.22.4",
                    "status": "affected",
                    "version": "4.21.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-26137",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-03T16:48:52.174175Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-03T17:10:16.886Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Bamboo Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.0.9",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.1.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.2.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Bamboo Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.0.9",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.1.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.2.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Bitbucket Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.6.16",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.19.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.20.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.21.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "8.0.0"
                },
                {
                  "status": "affected",
                  "version": "8.1.0"
                }
              ]
            },
            {
              "product": "Bitbucket Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.6.16",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.19.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.20.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.21.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "8.0.0"
                },
                {
                  "status": "affected",
                  "version": "8.1.0"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.18.0"
                }
              ]
            },
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.18.0"
                }
              ]
            },
            {
              "product": "Crowd Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "5.0.0"
                }
              ]
            },
            {
              "product": "Crowd Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "5.0.0"
                }
              ]
            },
            {
              "product": "Crucible",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.8.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Fisheye",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.8.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Core Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Software Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Software Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Service Management Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Service Management Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-07-20T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim\u2019s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-180",
                  "description": "Incorrect Behavior Order: Validate Before Canonicalize (CWE-180)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-20T17:25:23.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/BAM-21795"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/BSERV-13370"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5815"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/FE-7410"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CRUC-8541"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2022-07-20T00:00:00",
              "ID": "CVE-2022-26137",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Bamboo Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.0.9"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.1.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.2.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.2.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bamboo Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.0.9"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.1.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.2.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.2.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bitbucket Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.16"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.19.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.20.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.20.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.21.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.0.0"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bitbucket Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.16"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.19.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.20.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.20.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.21.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.0.0"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "7.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "7.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crowd Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.3.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.4.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.4.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crowd Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.3.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.4.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.4.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crucible",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.8.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Fisheye",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.8.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Core Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Software Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Software Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Service Management Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Service Management Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.22.4"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim\u2019s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Incorrect Behavior Order: Validate Before Canonicalize (CWE-180)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/BAM-21795",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/BAM-21795"
                },
                {
                  "name": "https://jira.atlassian.com/browse/BSERV-13370",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/BSERV-13370"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CONFSERVER-79476",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5815",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5815"
                },
                {
                  "name": "https://jira.atlassian.com/browse/FE-7410",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/FE-7410"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CRUC-8541",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CRUC-8541"
                },
                {
                  "name": "https://jira.atlassian.com/browse/JRASERVER-73897",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
                },
                {
                  "name": "https://jira.atlassian.com/browse/JSDSERVER-11863",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2022-26137",
        "datePublished": "2022-07-20T17:25:23.603Z",
        "dateReserved": "2022-02-25T00:00:00.000Z",
        "dateUpdated": "2024-10-03T17:10:16.886Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-26136 (GCVE-0-2022-26136)

    Vulnerability from cvelistv5 – Published: 2022-07-20 17:25 – Updated: 2024-10-03 16:43
    VLAI
    Summary
    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-03 15:26 UTC
    CWE
    • CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize (CWE-180).
    Impacted products
    Vendor Product Version
    Atlassian Bamboo Server Affected: unspecified , < 8.0.9 (custom)
    Affected: 8.1.0 , < unspecified (custom)
    Affected: unspecified , < 8.1.8 (custom)
    Affected: 8.2.0 , < unspecified (custom)
    Affected: unspecified , < 8.2.4 (custom)
    Create a notification for this product.
    Atlassian Bamboo Data Center Affected: unspecified , < 8.0.9 (custom)
    Affected: 8.1.0 , < unspecified (custom)
    Affected: unspecified , < 8.1.8 (custom)
    Affected: 8.2.0 , < unspecified (custom)
    Affected: unspecified , < 8.2.4 (custom)
    Create a notification for this product.
    Atlassian Bitbucket Server Affected: unspecified , < 7.6.16 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.8 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.19.5 (custom)
    Affected: 7.20.0 , < unspecified (custom)
    Affected: unspecified , < 7.20.2 (custom)
    Affected: 7.21.0 , < unspecified (custom)
    Affected: unspecified , < 7.21.2 (custom)
    Affected: 8.0.0
    Affected: 8.1.0
    Create a notification for this product.
    Atlassian Bitbucket Data Center Affected: unspecified , < 7.6.16 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.8 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.19.5 (custom)
    Affected: 7.20.0 , < unspecified (custom)
    Affected: unspecified , < 7.20.2 (custom)
    Affected: 7.21.0 , < unspecified (custom)
    Affected: unspecified , < 7.21.2 (custom)
    Affected: 8.0.0
    Affected: 8.1.0
    Create a notification for this product.
    Atlassian Confluence Server Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0
    Create a notification for this product.
    Atlassian Confluence Data Center Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0
    Create a notification for this product.
    Atlassian Crowd Server Affected: unspecified , < 4.3.8 (custom)
    Affected: 4.4.0 , < unspecified (custom)
    Affected: unspecified , < 4.4.2 (custom)
    Affected: 5.0.0
    Create a notification for this product.
    Atlassian Crowd Data Center Affected: unspecified , < 4.3.8 (custom)
    Affected: 4.4.0 , < unspecified (custom)
    Affected: unspecified , < 4.4.2 (custom)
    Affected: 5.0.0
    Create a notification for this product.
    Atlassian Crucible Affected: unspecified , < 4.8.10 (custom)
    Create a notification for this product.
    Atlassian Fisheye Affected: unspecified , < 4.8.10 (custom)
    Create a notification for this product.
    Atlassian Jira Core Server Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Software Server Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Software Data Center Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Service Management Server Affected: unspecified , < 4.13.22 (custom)
    Affected: 4.14.0 , < unspecified (custom)
    Affected: unspecified , < 4.20.10 (custom)
    Affected: 4.21.0 , < unspecified (custom)
    Affected: unspecified , < 4.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Service Management Data Center Affected: unspecified , < 4.13.22 (custom)
    Affected: 4.14.0 , < unspecified (custom)
    Affected: unspecified , < 4.20.10 (custom)
    Affected: 4.21.0 , < unspecified (custom)
    Affected: unspecified , < 4.22.4 (custom)
    Create a notification for this product.
    atlassian bamboo Affected: 7.2.0 , < 7.2.10 (custom)
    Affected: 8.0.0 , < 8.0.9 (custom)
    Affected: 8.1.0 , < 8.1.8 (custom)
    Affected: 8.2.0 , < 8.2.4 (custom)
        cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 0 , < 7.6.16 (custom)
    Affected: 7.7.0 , < 7.17.8 (custom)
    Affected: 7.18.0 , < 7.19.5 (custom)
    Affected: 7.20.0 , < 7.20.2 (custom)
    Affected: 7.21.0 , < 7.21.2 (custom)
        cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 8.0.0
    Affected: 8.1.0
        cpe:2.3:a:atlassian:bitbucket:8.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:bitbucket:8.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 0 , < 7.4.17 (custom)
    Affected: 7.5.0 , < 7.13.7 (custom)
    Affected: 7.14.0 , < 7.14.3 (custom)
    Affected: 7.15.0 , < 7.15.2 (custom)
    Affected: 7.16.0 , < 7.16.4 (custom)
    Affected: 7.17.0 , < 7.17.4 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 7.18.0
        cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 0 , < 7.4.17 (custom)
    Affected: 7.5.0 , < 7.13.7 (custom)
    Affected: 7.14.0 , < 7.14.3 (custom)
    Affected: 7.15.0 , < 7.15.2 (custom)
    Affected: 7.16.0 , < 7.16.4 (custom)
    Affected: 7.17.0 , < 7.17.4 (custom)
        cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 7.18.0
        cpe:2.3:a:atlassian:confluence_server:7.18.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crowd Affected: 0 , < 4.3.8 (custom)
    Affected: 4.4.0 , < 4.4.2 (custom)
        cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crowd Affected: 5.0.0
        cpe:2.3:a:atlassian:crowd:5.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crucible Affected: 0 , < 4.8.10 (custom)
        cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian fisheye Affected: 0 , < 4.8.10 (custom)
        cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_data_center Affected: 8.13.0 , < 8.13.22 (custom)
    Affected: 8.14.0 , < 8.20.10 (custom)
    Affected: 8.21.0 , < 8.22.4 (custom)
        cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_server Affected: 8.13.0 , < 8.13.22 (custom)
    Affected: 8.14.0 , < 8.20.10 (custom)
    Affected: 8.21.0 , < 8.22.4 (custom)
        cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_service_desk Affected: 0 , < 4.13.22 (custom)
        cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:server:*:*:*
    Create a notification for this product.
    atlassian jira_service_desk Affected: 0 , < 4.13.22 (custom)
        cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:data_center:*:*:*
    Create a notification for this product.
    atlassian jira_service_management Affected: 4.14.0 , < 4.20.10 (custom)
    Affected: 4.21.0 , < 4.22.4 (custom)
        cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*
    Create a notification for this product.
    atlassian jira_service_management Affected: 4.14.0 , < 4.20.10 (custom)
    Affected: 4.21.0 , < 4.22.4 (custom)
        cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*
    Create a notification for this product.
    Date Public
    2022-07-20 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:56:37.592Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/BAM-21795"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/BSERV-13370"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5815"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/FE-7410"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CRUC-8541"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bamboo",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.2.10",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.0.9",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.1.8",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.2.4",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.6.16",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.8",
                    "status": "affected",
                    "version": "7.7.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.19.5",
                    "status": "affected",
                    "version": "7.18.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.20.2",
                    "status": "affected",
                    "version": "7.20.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.21.2",
                    "status": "affected",
                    "version": "7.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:8.0.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:bitbucket:8.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.0.0"
                  },
                  {
                    "status": "affected",
                    "version": "8.1.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.4.17",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.13.7",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.14.3",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.15.2",
                    "status": "affected",
                    "version": "7.15.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.16.4",
                    "status": "affected",
                    "version": "7.16.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.4",
                    "status": "affected",
                    "version": "7.17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.18.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.4.17",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.13.7",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.14.3",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.15.2",
                    "status": "affected",
                    "version": "7.15.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.16.4",
                    "status": "affected",
                    "version": "7.16.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.4",
                    "status": "affected",
                    "version": "7.17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:7.18.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.18.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crowd",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.3.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.4.2",
                    "status": "affected",
                    "version": "4.4.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crowd:5.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crowd",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.0.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crucible",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.8.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fisheye",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.8.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.13.22",
                    "status": "affected",
                    "version": "8.13.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.20.10",
                    "status": "affected",
                    "version": "8.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.22.4",
                    "status": "affected",
                    "version": "8.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.13.22",
                    "status": "affected",
                    "version": "8.13.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.20.10",
                    "status": "affected",
                    "version": "8.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.22.4",
                    "status": "affected",
                    "version": "8.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:server:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_desk",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.13.22",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:data_center:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_desk",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.13.22",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_management",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.20.10",
                    "status": "affected",
                    "version": "4.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.22.4",
                    "status": "affected",
                    "version": "4.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_management",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.20.10",
                    "status": "affected",
                    "version": "4.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.22.4",
                    "status": "affected",
                    "version": "4.21.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-26136",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-03T15:26:49.090400Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-03T16:43:16.268Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Bamboo Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.0.9",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.1.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.2.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Bamboo Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.0.9",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.1.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.2.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Bitbucket Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.6.16",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.19.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.20.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.21.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "8.0.0"
                },
                {
                  "status": "affected",
                  "version": "8.1.0"
                }
              ]
            },
            {
              "product": "Bitbucket Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.6.16",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.19.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.20.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.21.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "8.0.0"
                },
                {
                  "status": "affected",
                  "version": "8.1.0"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.18.0"
                }
              ]
            },
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.18.0"
                }
              ]
            },
            {
              "product": "Crowd Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "5.0.0"
                }
              ]
            },
            {
              "product": "Crowd Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "5.0.0"
                }
              ]
            },
            {
              "product": "Crucible",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.8.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Fisheye",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.8.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Core Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Software Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Software Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Service Management Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Service Management Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-07-20T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-180",
                  "description": "Incorrect Behavior Order: Validate Before Canonicalize (CWE-180).",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-20T17:25:18.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/BAM-21795"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/BSERV-13370"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5815"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/FE-7410"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CRUC-8541"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2022-07-20T00:00:00",
              "ID": "CVE-2022-26136",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Bamboo Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.0.9"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.1.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.2.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.2.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bamboo Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.0.9"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.1.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.2.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.2.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bitbucket Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.16"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.19.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.20.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.20.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.21.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.0.0"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bitbucket Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.16"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.19.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.20.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.20.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.21.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.0.0"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "7.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "7.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crowd Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.3.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.4.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.4.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crowd Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.3.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.4.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.4.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crucible",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.8.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Fisheye",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.8.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Core Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Software Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Software Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Service Management Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Service Management Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.22.4"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Incorrect Behavior Order: Validate Before Canonicalize (CWE-180)."
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/BAM-21795",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/BAM-21795"
                },
                {
                  "name": "https://jira.atlassian.com/browse/BSERV-13370",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/BSERV-13370"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CONFSERVER-79476",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5815",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5815"
                },
                {
                  "name": "https://jira.atlassian.com/browse/FE-7410",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/FE-7410"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CRUC-8541",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CRUC-8541"
                },
                {
                  "name": "https://jira.atlassian.com/browse/JRASERVER-73897",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
                },
                {
                  "name": "https://jira.atlassian.com/browse/JSDSERVER-11863",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2022-26136",
        "datePublished": "2022-07-20T17:25:18.803Z",
        "dateReserved": "2022-02-25T00:00:00.000Z",
        "dateUpdated": "2024-10-03T16:43:16.268Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-36240 (GCVE-0-2020-36240)

    Vulnerability from cvelistv5 – Published: 2021-03-01 16:23 – Updated: 2024-09-17 01:22
    VLAI
    Summary
    The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.
    Severity
    No CVSS data available.
    CWE
    • Arbitrary File Read
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5685 x_refsource_MISC
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 4.0.4 (custom)
    Affected: 4.1.0 , < unspecified (custom)
    Affected: unspecified , < 4.1.2 (custom)
    Create a notification for this product.
    Date Public
    2021-02-28 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:23:09.980Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5685"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.0.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.1.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2021-02-28T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Arbitrary File Read",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-03-01T16:23:08.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5685"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2021-02-28T00:00:00",
              "ID": "CVE-2020-36240",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.0.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.1.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Arbitrary File Read"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5685",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5685"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2020-36240",
        "datePublished": "2021-03-01T16:23:08.996Z",
        "dateReserved": "2021-01-27T00:00:00.000Z",
        "dateUpdated": "2024-09-17T01:22:12.649Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-20902 (GCVE-0-2019-20902)

    Vulnerability from cvelistv5 – Published: 2020-10-01 01:30 – Updated: 2024-09-17 01:31
    VLAI
    Summary
    Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.
    Severity
    No CVSS data available.
    CWE
    • Broken Access Control
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5409 x_refsource_MISC
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 3.4.6 (custom)
    Affected: 3.5.0 , < unspecified (custom)
    Affected: unspecified , < 3.5.1 (custom)
    Create a notification for this product.
    Date Public
    2019-07-25 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T02:53:09.638Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5409"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "3.4.6",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.5.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2019-07-25T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Broken Access Control",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-10-01T01:30:19.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5409"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2019-07-25T00:00:00",
              "ID": "CVE-2019-20902",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.4.6"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.5.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Broken Access Control"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5409",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5409"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2019-20902",
        "datePublished": "2020-10-01T01:30:19.193Z",
        "dateReserved": "2020-07-07T00:00:00.000Z",
        "dateUpdated": "2024-09-17T01:31:07.490Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-20104 (GCVE-0-2019-20104)

    Vulnerability from cvelistv5 – Published: 2020-02-06 03:10 – Updated: 2024-09-16 17:04
    VLAI
    Summary
    The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
    Severity
    No CVSS data available.
    CWE
    • Improper Restriction of XML External Entity Reference
    References
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 3.6.2 (custom)
    Affected: 3.7.0 , < unspecified (custom)
    Affected: unspecified , < 3.7.1 (custom)
    Create a notification for this product.
    Date Public
    2020-02-05 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T02:32:10.611Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5526"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://zeroauth.ltd/blog/2020/02/07/cve-2019-20104-atlassian-crowd-openid-client-vulnerable-to-remote-dos-via-xml-entity-expansion/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "3.6.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.7.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2020-02-05T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Restriction of XML External Entity Reference",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-02-10T16:41:55.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5526"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://zeroauth.ltd/blog/2020/02/07/cve-2019-20104-atlassian-crowd-openid-client-vulnerable-to-remote-dos-via-xml-entity-expansion/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2020-02-05T00:00:00",
              "ID": "CVE-2019-20104",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.6.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.7.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.7.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Improper Restriction of XML External Entity Reference"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5526",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5526"
                },
                {
                  "name": "https://zeroauth.ltd/blog/2020/02/07/cve-2019-20104-atlassian-crowd-openid-client-vulnerable-to-remote-dos-via-xml-entity-expansion/",
                  "refsource": "MISC",
                  "url": "https://zeroauth.ltd/blog/2020/02/07/cve-2019-20104-atlassian-crowd-openid-client-vulnerable-to-remote-dos-via-xml-entity-expansion/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2019-20104",
        "datePublished": "2020-02-06T03:10:24.881Z",
        "dateReserved": "2019-12-30T00:00:00.000Z",
        "dateUpdated": "2024-09-16T17:04:16.877Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-18107 (GCVE-0-2017-18107)

    Vulnerability from cvelistv5 – Published: 2019-12-17 03:45 – Updated: 2024-09-16 20:06
    VLAI
    Summary
    Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default.
    Severity
    No CVSS data available.
    CWE
    • Cross-Site Request Forgery (CSRF)
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5091 x_refsource_MISC
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 3.1.1 (custom)
    Create a notification for this product.
    Date Public
    2019-02-07 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T21:13:48.099Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5091"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "3.1.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2019-02-07T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users \u0026 groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Cross-Site Request Forgery (CSRF)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-12-17T03:45:13.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5091"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2019-02-07T00:00:00",
              "ID": "CVE-2017-18107",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.1.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users \u0026 groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Cross-Site Request Forgery (CSRF)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5091",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5091"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2017-18107",
        "datePublished": "2019-12-17T03:45:13.620Z",
        "dateReserved": "2018-02-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:06:27.427Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-15005 (GCVE-0-2019-15005)

    Vulnerability from cvelistv5 – Published: 2019-11-08 03:55 – Updated: 2024-09-16 20:31
    VLAI
    Summary
    The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2.
    Severity
    No CVSS data available.
    CWE
    • Improper Authorization
    References
    Impacted products
    Vendor Product Version
    Atlassian Bitbucket Server Affected: unspecified , < 6.6.0 (custom)
    Create a notification for this product.
    Atlassian Jira Server Affected: unspecified , < 8.3.2 (custom)
    Create a notification for this product.
    Atlassian Confluence Server Affected: unspecified , < 7.0.1 (custom)
    Create a notification for this product.
    Atlassian Crowd Affected: unspecified , < 3.6.0 (custom)
    Create a notification for this product.
    Atlassian Fisheye Affected: unspecified , < 4.7.2 (custom)
    Create a notification for this product.
    Atlassian Crucible Affected: unspecified , < 4.7.2 (custom)
    Create a notification for this product.
    Atlassian Bamboo Affected: unspecified , < 6.10.2 (custom)
    Create a notification for this product.
    Date Public
    2019-11-08 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T00:34:53.099Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/BAM-20647"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://herolab.usd.de/security-advisories/usd-2019-0016/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Bitbucket Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "6.6.0",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.3.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.0.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "3.6.0",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Fisheye",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.7.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Crucible",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.7.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Bamboo",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "6.10.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2019-11-08T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Authorization",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-11-14T20:44:03.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/BAM-20647"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://herolab.usd.de/security-advisories/usd-2019-0016/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2019-11-08T00:00:00",
              "ID": "CVE-2019-15005",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Bitbucket Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "6.6.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.3.2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.0.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.6.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Fisheye",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.7.2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crucible",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.7.2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bamboo",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "6.10.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Improper Authorization"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/BAM-20647",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/BAM-20647"
                },
                {
                  "name": "https://herolab.usd.de/security-advisories/usd-2019-0016/",
                  "refsource": "MISC",
                  "url": "https://herolab.usd.de/security-advisories/usd-2019-0016/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2019-15005",
        "datePublished": "2019-11-08T03:55:12.611Z",
        "dateReserved": "2019-08-13T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:31:42.718Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-11580 (GCVE-0-2019-11580)

    Vulnerability from cvelistv5 – Published: 2019-06-03 13:43 – Updated: 2025-10-21 23:45
    VLAI
    Summary
    Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-07 12:27 UTC
    CWE
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: 2.1.0 , < unspecified (custom)
    Affected: unspecified , < 3.0.5 (custom)
    Affected: 3.1.0 , < unspecified (custom)
    Affected: unspecified , < 3.1.6 (custom)
    Affected: 3.2.0 , < unspecified (custom)
    Affected: unspecified , < 3.2.8 (custom)
    Affected: 3.3.0 , < unspecified (custom)
    Affected: unspecified , < 3.3.5 (custom)
    Affected: 3.4.0 , < unspecified (custom)
    Affected: unspecified , < 3.4.4 (custom)
    Create a notification for this product.
    Date Public
    2019-05-22 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:55:41.035Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5388"
              },
              {
                "name": "108637",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/108637"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2019-11580",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-07T12:27:38.420089Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2021-11-03",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11580"
                  },
                  "type": "kev"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "description": "CWE-noinfo Not enough information",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:45:35.696Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11580"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2021-11-03T00:00:00.000Z",
                "value": "CVE-2019-11580 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.0.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.1.6",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.2.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.3.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.3.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.4.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2019-05-22T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Leftover Debug Code",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-08-12T17:06:12.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5388"
            },
            {
              "name": "108637",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/108637"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2019-05-22T00:00:00",
              "ID": "CVE-2019-11580",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003e=",
                                "version_value": "2.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.0.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.1.6"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.2.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.2.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.3.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.3.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.4.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.4.4"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Leftover Debug Code"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5388",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5388"
                },
                {
                  "name": "108637",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/108637"
                },
                {
                  "name": "http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.html",
                  "refsource": "MISC",
                  "url": "http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2019-11580",
        "datePublished": "2019-06-03T13:43:48.001Z",
        "dateReserved": "2019-04-29T00:00:00.000Z",
        "dateUpdated": "2025-10-21T23:45:35.696Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-18110 (GCVE-0-2017-18110)

    Vulnerability from cvelistv5 – Published: 2019-03-29 14:04 – Updated: 2024-09-16 18:08
    VLAI
    Summary
    The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.
    Severity
    No CVSS data available.
    CWE
    • Improper Restriction of XML External Entity Reference ('XXE')
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5070 x_refsource_MISC
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 3.0.2 (custom)
    Affected: 3.1.0 , < unspecified (custom)
    Affected: unspecified , < 3.1.1 (custom)
    Create a notification for this product.
    Date Public
    2018-03-23 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T21:13:48.200Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5070"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "3.0.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.1.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2018-03-23T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Restriction of XML External Entity Reference (\u0027XXE\u0027)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-29T14:04:53.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5070"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2018-03-23T00:00:00",
              "ID": "CVE-2017-18110",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.0.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.1.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Improper Restriction of XML External Entity Reference (\u0027XXE\u0027)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5070",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5070"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2017-18110",
        "datePublished": "2019-03-29T14:04:53.296Z",
        "dateReserved": "2018-02-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T18:08:23.904Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-18109 (GCVE-0-2017-18109)

    Vulnerability from cvelistv5 – Published: 2019-03-29 14:04 – Updated: 2024-09-16 17:08
    VLAI
    Summary
    The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
    Severity
    No CVSS data available.
    CWE
    • URL Redirection to Untrusted Site ('Open Redirect')
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5071 x_refsource_MISC
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 3.0.2 (custom)
    Affected: 3.1.0 , < unspecified (custom)
    Affected: unspecified , < 3.1.1 (custom)
    Create a notification for this product.
    Date Public
    2018-03-23 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T21:13:48.570Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5071"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "3.0.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.1.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2018-03-23T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-29T14:04:53.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5071"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2018-03-23T00:00:00",
              "ID": "CVE-2017-18109",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.0.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.1.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5071",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5071"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2017-18109",
        "datePublished": "2019-03-29T14:04:53.255Z",
        "dateReserved": "2018-02-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T17:08:13.135Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-18108 (GCVE-0-2017-18108)

    Vulnerability from cvelistv5 – Published: 2019-03-29 14:04 – Updated: 2024-09-16 22:30
    VLAI
    Summary
    The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5062 x_refsource_MISC
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 2.10.2 (custom)
    Create a notification for this product.
    Date Public
    2018-04-16 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T21:13:48.822Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5062"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "2.10.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2018-04-16T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-29T14:04:53.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5062"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2018-04-16T00:00:00",
              "ID": "CVE-2017-18108",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "2.10.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5062",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5062"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2017-18108",
        "datePublished": "2019-03-29T14:04:53.218Z",
        "dateReserved": "2018-02-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T22:30:08.235Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-18106 (GCVE-0-2017-18106)

    Vulnerability from cvelistv5 – Published: 2019-03-29 14:04 – Updated: 2024-09-16 23:40
    VLAI
    Summary
    The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another user's session provided they can make their identifier hash collide with another user's session identifier hash.
    Severity
    No CVSS data available.
    CWE
    • Use of a Broken or Risky Cryptographic Algorithm
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5061 x_refsource_MISC
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 2.9.1 (custom)
    Create a notification for this product.
    Date Public
    2019-03-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T21:13:48.419Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5061"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "2.9.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2019-03-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another user\u0027s session provided they can make their identifier hash collide with another user\u0027s session identifier hash."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use of a Broken or Risky Cryptographic Algorithm",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-29T14:04:53.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5061"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2019-03-04T00:00:00",
              "ID": "CVE-2017-18106",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "2.9.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another user\u0027s session provided they can make their identifier hash collide with another user\u0027s session identifier hash."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Use of a Broken or Risky Cryptographic Algorithm"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5061",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5061"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2017-18106",
        "datePublished": "2019-03-29T14:04:53.177Z",
        "dateReserved": "2018-02-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T23:40:45.456Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-18105 (GCVE-0-2017-18105)

    Vulnerability from cvelistv5 – Published: 2019-03-29 14:04 – Updated: 2024-09-16 20:42
    VLAI
    Summary
    The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability.
    Severity
    No CVSS data available.
    CWE
    • Session Fixation
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5072 x_refsource_MISC
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 3.0.2 (custom)
    Affected: 3.1.0 , < unspecified (custom)
    Affected: unspecified , < 3.1.1 (custom)
    Create a notification for this product.
    Date Public
    2018-03-23 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T21:13:48.142Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5072"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "3.0.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.1.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2018-03-23T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user\u0027s JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Session Fixation",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-03-29T14:04:53.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5072"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2018-03-23T00:00:00",
              "ID": "CVE-2017-18105",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.0.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.1.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user\u0027s JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Session Fixation"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5072",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5072"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2017-18105",
        "datePublished": "2019-03-29T14:04:53.127Z",
        "dateReserved": "2018-02-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:42:15.439Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-20238 (GCVE-0-2018-20238)

    Vulnerability from cvelistv5 – Published: 2019-02-13 18:00 – Updated: 2024-09-16 20:41
    VLAI
    Summary
    Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
    Severity
    No CVSS data available.
    CWE
    • Insufficient Session Expiration
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5361 x_refsource_CONFIRM
    http://www.securityfocus.com/bid/107036 vdb-entryx_refsource_BID
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: unspecified , < 3.2.7 (custom)
    Affected: 3.3.0 , < unspecified (custom)
    Affected: unspecified , < 3.3.4 (custom)
    Create a notification for this product.
    Date Public
    2019-02-13 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T11:58:19.098Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5361"
              },
              {
                "name": "107036",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/107036"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "3.2.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "3.3.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "3.3.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2019-02-13T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Insufficient Session Expiration",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-02-16T10:57:01.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5361"
            },
            {
              "name": "107036",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/107036"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2019-02-13T00:00:00",
              "ID": "CVE-2018-20238",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.2.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "3.3.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "3.3.4"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Insufficient Session Expiration"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5361",
                  "refsource": "CONFIRM",
                  "url": "https://jira.atlassian.com/browse/CWD-5361"
                },
                {
                  "name": "107036",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/107036"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2018-20238",
        "datePublished": "2019-02-13T18:00:00.000Z",
        "dateReserved": "2018-12-19T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:41:48.136Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-16858 (GCVE-0-2017-16858)

    Vulnerability from cvelistv5 – Published: 2018-01-31 14:00 – Updated: 2024-09-17 00:40
    VLAI
    Summary
    The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crowd user in REST requests by being able to authenticate to a directory bound to an application using the feature. Given the following situation: the Crowd application is bound to directory 1 and has a user called admin and the Google Apps application is bound to directory 2, which also has a user called admin, it was possible to authenticate REST requests using the credentials of the user coming from directory 2 and impersonate the user from directory 1.
    Severity
    No CVSS data available.
    CWE
    • CWE-863 - Incorrect Authorization (CWE-863)
    References
    URL Tags
    https://jira.atlassian.com/browse/CWD-5009 x_refsource_CONFIRM
    Impacted products
    Vendor Product Version
    Atlassian Crowd Affected: from 1.5.0 before 3.1.2
    Create a notification for this product.
    Date Public
    2018-01-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T20:35:21.278Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5009"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Crowd",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "from 1.5.0 before 3.1.2"
                }
              ]
            }
          ],
          "datePublic": "2018-01-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The \u0027crowd-application\u0027 plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crowd user in REST requests by being able to authenticate to a directory bound to an application using the feature. Given the following situation: the Crowd application is bound to directory 1 and has a user called admin and the Google Apps application is bound to directory 2, which also has a user called admin, it was possible to authenticate REST requests using the credentials of the user coming from directory 2 and impersonate the user from directory 1."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization (CWE-863)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-01-31T13:57:01.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5009"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2018-01-30T00:00:00",
              "ID": "CVE-2017-16858",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Crowd",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "from 1.5.0 before 3.1.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The \u0027crowd-application\u0027 plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crowd user in REST requests by being able to authenticate to a directory bound to an application using the feature. Given the following situation: the Crowd application is bound to directory 1 and has a user called admin and the Google Apps application is bound to directory 2, which also has a user called admin, it was possible to authenticate REST requests using the credentials of the user coming from directory 2 and impersonate the user from directory 1."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Incorrect Authorization (CWE-863)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5009",
                  "refsource": "CONFIRM",
                  "url": "https://jira.atlassian.com/browse/CWD-5009"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2017-16858",
        "datePublished": "2018-01-31T14:00:00.000Z",
        "dateReserved": "2017-11-16T00:00:00.000Z",
        "dateUpdated": "2024-09-17T00:40:54.506Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }