CVE-2019-20902

Publication date

2020-10-01 01:30:19

Family

atlassian

State

PUBLISHED

Description

Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.