First published: Thu Oct 01 2020(Updated: )
Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Crowd | <3.4.6 | |
Atlassian Crowd | >=3.5.0<3.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20902 is a vulnerability in Atlassian Crowd that allows reactivation of a disabled user from OpenLDAP during an upgrade via XML Data Transfer.
The severity of CVE-2019-20902 is high with a CVSS score of 7.5.
CVE-2019-20902 affects Atlassian Crowd versions prior to 3.4.6 and versions from 3.5.0 before 3.5.1.
To fix CVE-2019-20902, upgrade Atlassian Crowd to version 3.4.6 or higher, or upgrade to version 3.5.1 or higher if you are using versions in the range of 3.5.0 to 3.5.1.
You can find more information about CVE-2019-20902 in the Atlassian issue tracker: [CVE-2019-20902](https://jira.atlassian.com/browse/CWD-5409).