Lucene search

K
cvelistAtlassianCVELIST:CVE-2019-20902
HistoryOct 01, 2020 - 1:30 a.m.

CVE-2019-20902

2020-10-0101:30:19
atlassian
www.cve.org
4
cve-2019-20902
crowd
xml data transfer
openldap
security vulnerability

EPSS

0.001

Percentile

42.2%

Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.

CNA Affected

[
  {
    "product": "Crowd",
    "vendor": "Atlassian",
    "versions": [
      {
        "lessThan": "3.4.6",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "3.5.0",
        "versionType": "custom"
      },
      {
        "lessThan": "3.5.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

42.2%

Related for CVELIST:CVE-2019-20902