If your company is using any version of Atlassian Software Systems' Crowd offering preceding version 2.5.4, it is vulnerable to this latest exploit, which allows malicious users to craft specially formulated URLs that trick the server into returning all files that reside on it, including configuration files and other files that contain user credentials.