
Cloud Vulnerability DB
A community-led vulnerabilities database
Atlassian Crowd versions released after 3.0.0 were affected by a critical security misconfiguration vulnerability (CVE-2022-43782) that was discovered through an internal security review by Ashish Kotha. The vulnerability allows an attacker to authenticate as the Crowd application by bypassing password checks and call privileged endpoints in Crowd's REST API under the usermanagement path. This vulnerability only affects new installations of Crowd and can only be exploited by IPs specified under the Crowd application's allowlist in the Remote Addresses configuration, which is none by default (Atlassian Advisory).
The vulnerability received a CVSS v3.1 base score of 9.8 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The affected versions include Crowd 3.0.0 - 3.7.2, Crowd 4.0.0 - 4.4.3, and Crowd 5.0.0 - 5.0.2. The vulnerability specifically affects new installations and not instances that were upgraded from versions prior to 3.0.0 (NVD, Atlassian Advisory).
If successfully exploited, the vulnerability allows attackers to authenticate as the Crowd application and access privileged endpoints in Crowd's REST API under the usermanagement path. This could potentially lead to unauthorized access and control over user management functions. The impact is limited to instances where IP addresses have been explicitly added to the Remote Address configuration (Hacker News).
Atlassian recommends upgrading to fixed versions: 5.0.3 or later for Crowd 5.0, 4.4.4 or later for Crowd 4.0. For Crowd 3.0, which is deprecated, no fix is available and users must upgrade to version 4.4.4 or 5.0.3. As a temporary mitigation, users can remove any entries in the 'Remote Addresses' tab for the Crowd application and change the application's password to a stronger one (Atlassian Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."