Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-5060

Various resources included the current remote directory password in their responses - CVE-2016-10740

      Various resources in Atlassian Crowd before before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories via examining the responses of various resources.

            [CWD-5060] Various resources included the current remote directory password in their responses - CVE-2016-10740

            Said made changes -
            Labels Original: CVE-2016-10740 advisory advisory-released cvss-medium security New: CVE-2016-10740 advisory advisory-released cvss-medium information-disclosure security
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 - restricted [ 2642973 ] New: JAC Bug Workflow v3 [ 3365786 ]
            David Black made changes -
            Labels Original: CVE-2016-10740 advisory advisory-to-release cvss-medium security New: CVE-2016-10740 advisory advisory-released cvss-medium security
            David Black made changes -
            Labels Original: advisory advisory-to-release cvss-medium security New: CVE-2016-10740 advisory advisory-to-release cvss-medium security
            David Black made changes -
            Summary Original: Various resources included the current remote directory password in their responses New: Various resources included the current remote directory password in their responses - CVE-2016-10740
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release breaches-security-sla cvss-medium security New: advisory advisory-to-release cvss-medium security
            Owen made changes -
            Symptom Severity Original: Critical [ 14430 ] New: Severity 1 - Critical [ 15830 ]
            David Black made changes -
            Priority Original: Low [ 4 ] New: Medium [ 3 ]
            David Black made changes -
            Description Original: Component in Atlassian Crowd from version 2.8 before version 2.10.1 and from version 2.9.1 before version 2.10.1 allows remote attackers to IMPACT via a VULN_INFO. New: Various resources in Atlassian Crowd before before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories via examining the responses of various resources.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: