CVE-2017-18106 Vulnerability Details

  /     /     /  

CVE-2017-18106 Metadata Quick Info

CVE Published: 29/03/2019 | CVE Updated: 16/09/2024 | CVE Year: 2017
Source: atlassian | Vendor: Atlassian | Product: Crowd
Status : PUBLISHED

CVE-2017-18106 Description

The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another user\'s session provided they can make their identifier hash collide with another user\'s session identifier hash.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Use of a Broken or Risky Cryptographic Algorithm
Source: Atlassian

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).