Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Atlassian Crowd 安全漏洞
Vulnerability Description
Atlassian Crowd是澳大利亚Atlassian公司的一套基于Web的单点登录系统。该系统为多用户、网络应用程序和目录服务器提供验证、授权等功能。 Atlassian Crowd 2.9.5之前的2.9.x版本和2.8.8之前的版本中的LDAP目录连接器存在安全漏洞。远程攻击者可借助带有特制序列化Java对象的LDAP利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A