LDAP Password Exposure in Atlassian Crowd by Remote Administrators
CVE-2016-10740
4.9MEDIUM
What is CVE-2016-10740?
In versions of Atlassian Crowd prior to 2.10.1, an issue exists that allows remote attackers, possessing administrative privileges, to extract passwords of configured LDAP directories. This is achieved by analyzing the responses generated from specific resource requests, which compromises the security of sensitive authentication credentials.