cve/2019/CVE-2019-20104.md

18 lines
841 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-20104](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20104)
![](https://img.shields.io/static/v1?label=Product&message=Crowd&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%203.6.2%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Improper%20Restriction%20of%20XML%20External%20Entity%20Reference&color=brighgreen)
### Description
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
### POC
#### Reference
- https://zeroauth.ltd/blog/2020/02/07/cve-2019-20104-atlassian-crowd-openid-client-vulnerable-to-remote-dos-via-xml-entity-expansion/
#### Github
No PoCs found on GitHub currently.