VYPR
Critical severity9.8NVD Advisory· Published Nov 17, 2022· Updated Jun 17, 2026

CVE-2022-43782

CVE-2022-43782

Description

Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path.

This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default.

The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Atlassian/Crowd2 versions
    cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*range: >=3.0.0,<4.4.4
    • (no CPE)range: <4.4.4, <5.0.3, all 3.x.x
  • Range: before 4.4.4
  • Atlassian/Crowd Serverv5
    Range: before 4.4.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.