Junglewise Threat Intelligence

CVE-2019-11580: Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

CVE-2019-11580 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Atlassian.

Executive brief

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability because the pdkinstall development plugin was incorrectly enabled in release builds. Unauthenticated attackers can exploit this to install arbitrary plugins, leading to full system compromise.

Affected products

  • Atlassian Crowd 2.1.0 to < 3.0.5, 3.1.0 to < 3.1.6, 3.2.0 to < 3.2.8, 3.3.0 to < 3.3.5, 3.4.0 to < 3.4.4
  • Atlassian Crowd Data Center 2.1.0 to < 3.0.5, 3.1.0 to < 3.1.6, 3.2.0 to < 3.2.8, 3.3.0 to < 3.3.5, 3.4.0 to < 3.4.4

Timeline

  • 2019-06-03: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild