CVE-2019-20902: High severity atlassian crowd vulnerability
Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20902?
CVE-2019-20902 is a vulnerability in Atlassian Crowd that allows reactivation of a disabled user from OpenLDAP during an upgrade via XML Data Transfer.
What is the severity of CVE-2019-20902?
The severity of CVE-2019-20902 is high with a CVSS score of 7.5.
How does CVE-2019-20902 affect Atlassian Crowd?
CVE-2019-20902 affects Atlassian Crowd versions prior to 3.4.6 and versions from 3.5.0 before 3.5.1.
How can I fix CVE-2019-20902?
To fix CVE-2019-20902, upgrade Atlassian Crowd to version 3.4.6 or higher, or upgrade to version 3.5.1 or higher if you are using versions in the range of 3.5.0 to 3.5.1.
Where can I find more information about CVE-2019-20902?
You can find more information about CVE-2019-20902 in the Atlassian issue tracker: [CVE-2019-20902](https://jira.atlassian.com/browse/CWD-5409).