Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-43782
HistoryNov 17, 2022 - 12:15 a.m.

Path traversal

2022-11-1700:15:00
PRIOn knowledge base
www.prio-n.com
9
atlassian crowd
path traversal
security misconfiguration
rest api
remote addresses
vulnerability
ip allowlist

9.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.2%

Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd’s REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3

CPENameOperatorVersion
crowdge5.0.0
crowdlt5.0.3
crowdge3.0.0
crowdlt4.4.4

9.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.2%

Related for PRION:CVE-2022-43782