CVE-2017-18110: Atlassian Crowd

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.

Affected products

  • Atlassian Crowd: before 3.0.2 (fixed in 3.0.2); version 3.1.0 only

Published 2019-03-29. Last modified 2026-06-17.