CVE-2019-20104: High severity atlassian crowd vulnerability
Published Feb 6, 2020
·Updated
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
Affected Software
7 affected components
Atlassian crowd<3.2.11
Atlassian crowd>=3.3.0<3.3.8
Atlassian crowd>=3.4.0<3.4.7
Atlassian crowd>=3.5.0<3.5.2
Atlassian crowd>=3.6.0<3.6.2
Atlassian crowd>=3.6.3<3.7.1
Atlassian crowd>=3.7.2<4.0.0
Event History
Feb 6, 2020
CVE Published
via MITRE·03:10 AM
Data Sourced
via MITRE·03:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-20104.
2
What is the severity of CVE-2019-20104?
The severity of CVE-2019-20104 is high with a severity value of 7.5.
3
How does CVE-2019-20104 affect the Atlassian Crowd application?
CVE-2019-20104 affects Atlassian Crowd before version 3.6.2 and from version 3.7.0 before 3.7.1.
4
What is the impact of CVE-2019-20104?
The impact of CVE-2019-20104 is a Denial of Service (DoS) attack through an XML Entity Expansion vulnerability.
5
How can I fix CVE-2019-20104 in Atlassian Crowd?
To fix CVE-2019-20104, it is recommended to upgrade Atlassian Crowd to version 3.6.2 or apply version 3.7.1 or later.