The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another user's session provided they can make their identifier hash collide with another user's session identifier hash.
                
            References
                    | Link | Resource | 
|---|---|
| https://jira.atlassian.com/browse/CWD-5061 | Issue Tracking Vendor Advisory | 
| https://jira.atlassian.com/browse/CWD-5061 | Issue Tracking Vendor Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2019-03-29 14:29
Updated : 2024-11-21 03:19
NVD link : CVE-2017-18106
Mitre link : CVE-2017-18106
CVE.ORG link : CVE-2017-18106
JSON object : View
Products Affected
                atlassian
- crowd
 
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
