CVE-2016-6496
Crowd LDAP Java Object Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
El conector de directorio LDAP en Atlassian Crowd en versiones anteriores a 2.8.8 y 2.9.x en versiones anteriores a 2.9.5 permite a atacantes remotos ejecutar código arbitrario a través de un atributo LDAP con un objeto Java serializado manipulado, también conocido como envenenamiento de entrada LDAP.
This advisory discloses a critical severity security vulnerability which was introduced in version 1.4.1 of Crowd. Versions of Crowd starting with 1.4.1 before 2.8.8 (the fixed version for 2.8.x) and from 2.9.0 before 2.9.5 (the fixed version for 2.9.x) are affected by this vulnerability. The Crowd LDAP directory connector allowed an attacker to gain remote code execution in Crowd by injecting malicious attributes in LDAP entries.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-08-01 CVE Reserved
- 2016-10-31 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/539655/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/93826 | Third Party Advisory | |
https://jira.atlassian.com/browse/CWD-4790 | Issue Tracking | |
https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf | Not Applicable |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://confluence.atlassian.com/crowd/crowd-security-advisory-2016-10-19-856697283.html | 2018-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Crowd Search vendor "Atlassian" for product "Crowd" | <= 2.8.4 Search vendor "Atlassian" for product "Crowd" and version " <= 2.8.4" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Crowd Search vendor "Atlassian" for product "Crowd" | 2.9.0 Search vendor "Atlassian" for product "Crowd" and version "2.9.0" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Crowd Search vendor "Atlassian" for product "Crowd" | 2.9.1 Search vendor "Atlassian" for product "Crowd" and version "2.9.1" | - |
Affected
|