Beveiligingsadvies

CVE-2017-18107

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-12-17 03:45:13
Laatst bijgewerkt 2024-09-16 20:06:27
Toegewezen door atlassian
CVSS-score geen score
Status PUBLISHED

Beschrijving

Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default.