CVE-2022-43782
Estado: ModificadaCrítica (9.8)—
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path.
This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default.
The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.95%
- Percentil entre todas las CVEs puntuadas: 60
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-43782",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-43782",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-10-02T15:01:35.451793Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@atlassian.com",
"affectedData": [
{
"vendor": "Atlassian",
"product": "Crowd Data Center",
"versions": [
{
"status": "unaffected",
"version": "before 3.0.0"
},
{
"status": "affected",
"version": "before 4.4.4"
},
{
"status": "affected",
"version": "before 5.0.3"
}
]
},
{
"vendor": "Atlassian",
"product": "Crowd Server",
"versions": [
{
"status": "unaffected",
"version": "before 3.0.0"
},
{
"status": "affected",
"version": "before 4.4.4"
},
{
"status": "affected",
"version": "before 5.0.3"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*"
],
"vendor": "atlassian",
"product": "crowd",
"versions": [
{
"status": "affected",
"version": "3.0.0",
"lessThan": "4.4.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.0.0",
"lessThan": "5.0.3",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2022-11-17T00:15:18.640",
"references": [
{
"url": "https://jira.atlassian.com/browse/CWD-5888",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "security@atlassian.com"
},
{
"url": "https://jira.atlassian.com/browse/CWD-5888",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path.\n\nThis vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default.\n\nThe affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3"
},
{
"lang": "es",
"value": "Las versiones afectadas de Atlassian Crowd permiten a un atacante autenticarse como aplicación multitud a través de una mala configuración de seguridad y la posterior capacidad de llamar a endpoints privilegiados en la API REST de Crowd bajo la ruta {{usermanagement}}. Esta vulnerabilidad solo puede ser explotada por las IP especificadas en la lista de aplicaciones permitidas en la configuración de Direcciones Remotas, que es {{none}} de forma predeterminada. Las versiones afectadas son todas las versiones 3.xx, versiones 4.xx anteriores a la versión 4.4.4 y versiones 5.xx anteriores a 5.0.3."
}
],
"lastModified": "2026-06-17T05:07:20.553",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CCF91D4-43A1-487C-B52B-73C6544B5BB8",
"versionEndExcluding": "4.4.4",
"versionStartIncluding": "3.0.0"
},
{
"criteria": "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95559CCB-370F-4E26-B9B6-BFD31F088AAC",
"versionEndExcluding": "5.0.3",
"versionStartIncluding": "5.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@atlassian.com"
}