Critical vulnerabilities found in single sign-on enterprise tool Atlassian Crowd

One critical vulnerability was fixed, but a second one remains unpatched, security researchers from Command Five said

A critical vulnerability that could allow remote attackers to access sensitive enterprise log-in credentials and other data was fixed last week in Crowd, a single sign-on (SSO) and identity management tool used by large organizations to simplify access to their internal Web applications and services.

According to Atlassian, the Sydney-based software company that develops Crowd, the product is used by around 1,000 organizations in 55 countries, including large banks, car manufacturers, government agencies, telecommunication companies, software firms, online services providers, universities and others.

Crowd can be used to link identities between Active Directory, LDAP and other directory services; Atlassian's popular bug tracking, collaboration, project management and code repository tools; third party services like Google Apps, Apache or Subversion, and custom in-house developed Web applications.

The newly patched vulnerability stems from the way in which Crowd parses external XML entities defined in Document Type Definition (DTD) headers and is a variation of a vulnerability known as CVE-2012-2926 that was reported and patched back in 2012, researchers from security consultancy firm Command Five said Friday in a security advisory.

An attacker can exploit the vulnerability by sending requests with specially crafted entity URLs in order to trick the server into returning any file from the internal network that it has access to, including its own configuration files that contain unencrypted credentials, or to initiate a denial-of-service attack that would make the server inaccessible to users.

The 2012 vulnerability, for which an exploit module already exists in the Metasploit penetration testing tool, was fixed in Crowd 2.4.1. However, that patch only blocks external entities defined in requests sent to Crowd URLs that end in "/services," the Command Five researchers said.

Versions of Crowd up to and including 2.6.2 continue to process entities defined in DTD headers for requests that are sent to URLs ending in "/services/2" or "/services/latest," which re-enables the exploit, they said. "With a two character change to the targeted URL the Metasploit module is again 'fully armed and operational'."

The new issue has been assigned the CVE-2013-3925 identifier and was fixed in the latest stable version of the product, Crowd 2.6.3, that was released on June 24. According to the corresponding entry in Atlassian's bug tracker, the vulnerability has also been fixed in versions 2.5.4 and 2.7.

"Successful exploitation of this vulnerability can (but does not necessarily) lead to a hacker taking full control of an organization's single sign-on service, potentially resulting in a catastrophic security event," the Command Five researchers said in their advisory. At the very least, successful exploitation is likely to enable attackers to expand their unauthorized access within the targeted organization, they said.

Organizations that expose their Crowd installations to the Internet in order to enable remote authentication for employees or affiliates are at increased risk of suffering a security breach, the researchers said.

Aside from this patched vulnerability, Command Five is also aware of at least another critical vulnerability in Atlassian Crowd that hasn't been fixed yet. That vulnerability could be classified as a backdoor and allows unauthenticated attackers to take full control of any Crowd server they can access over the network, the researchers said.

Successful exploitation of the yet-to-be-patched vulnerability "invariably results" in the compromise of all active Crowd application credentials, user credentials, accessible data storage, configured directories and dependent secure systems, they said.

Atlassian didn't immediately respond to a request for comment.

Tags: Command Five, patches, atlassian, security, Access control and authentication, Exploits / vulnerabilities

Lower costs help NZ pip Australia for F5 Networks support centre

READ THIS ARTICLE
DO NOT SHOW THIS BOX AGAIN [ x ]
Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

SECURE Web Gateway

Balancing the requirement for strong network security with the need to harness collaborative web technologies is essential for business growth.

Latest Jobs
Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.