Get a Pentest and security assessment of your IT network.

News

Critical vulnerabilities found in single sign-on enterprise tool Atlassian Crowd

A critical vulnerability has been fixed in Crowd, a single sign-on (SSO) and identity management tool used by large organizations. The vulnerability stems from the way in which Crowd parses external XML entities defined in Document Type Definition (DTD) headers. An attacker can exploit the vulnerability by sending requests with specially crafted entity URLs in order to trick the server into returning any file from the internal network that it has access to. The new issue has been assigned the CVE-2013-3925 identifier and was fixed in the latest stable version of the product.”]

Source: https://www.csoonline.com/article/2133670/critical-vulnerabilities-found-in-single-sign-on-enterprise-tool-atlassian-crowd.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks