Security News > 2019 > July > Researcher releases PoC code for critical Atlassian Crowd RCE flaw

Researcher releases PoC code for critical Atlassian Crowd RCE flaw
2019-07-16 09:41

A researcher has released proof-of-concept code for a critical code execution vulnerability (CVE-2019-11580) in Atlassian Crowd, a centralized identity management solution providing single sign-on and user identity. Atlassian plugged the hole in late May, but administrators that failed to implement it should consider doing so now, as full-fledged exploits are likely to pop up soon. About the vulnerability (CVE-2019-11580) Atlassian Crowd allows enterprise admins to manage users from Active Directory, LDAP, OpenLDAP or Microsoft Azure … More → The post Researcher releases PoC code for critical Atlassian Crowd RCE flaw appeared first on Help Net Security.


News URL

http://feedproxy.google.com/~r/HelpNetSecurity/~3/-mfZjZ4lZOs/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2019-06-03 CVE-2019-11580 Unspecified vulnerability in Atlassian Crowd
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds.
network
low complexity
atlassian
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Atlassian 58 3 259 104 46 412