#VU31132 Open redirect in Crowd Server - CVE-2017-18109
Published: March 29, 2019 / Updated: July 17, 2020
Crowd Server
Atlassian
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.