VYPR
High severity7.5NVD Advisory· Published Feb 6, 2020· Updated Jun 17, 2026

CVE-2019-20104

CVE-2019-20104

Description

The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Atlassian/Crowd3 versions
    cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*range: <3.2.11
    • (no CPE)range: <3.6.2, 3.7.0 < 3.7.1
    • (no CPE)range: unspecified
  • Range: <3.6.2, 3.7.0 < 3.7.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.