-
Bug
-
Resolution: Fixed
-
Low
-
None
-
None
-
Severity 2 - Major
-
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default.
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 6.1 => Medium severity
Exploitability Metrics
Scope Metric
Impact Metrics