CVE-2019-20104: Atlassian Crowd

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.

Affected products

  • Atlassian Crowd: before 3.2.11 (fixed in 3.2.11); from 3.3.0, before 3.3.8 (fixed in 3.3.8); from 3.4.0, before 3.4.7 (fixed in 3.4.7); from 3.5.0, before 3.5.2 (fixed in 3.5.2); from 3.6.0, before 3.6.2 (fixed in 3.6.2); from 3.6.3, before 3.7.1 (fixed in 3.7.1); …

Published 2020-02-06. Last modified 2026-06-17.