CVE-2022-43782

CRITICAL

Atlassian Crowd <4.4.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3

References (1)

Core 1
Core References
Issue Tracking, Patch, Vendor Advisory
https://jira.atlassian.com/browse/CWD-5888

Scores

CVSS v3 9.8
EPSS 0.0085
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

Status published
Products (1)
atlassian/crowd 3.0.0 - 4.4.4
Published Nov 17, 2022
Tracked Since Feb 18, 2026