Executive brief
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability because the pdkinstall development plugin was incorrectly enabled in release builds. Unauthenticated attackers can exploit this to install arbitrary plugins, leading to full system compromise.
Affected products
- Atlassian Crowd 2.1.0 to < 3.0.5, 3.1.0 to < 3.1.6, 3.2.0 to < 3.2.8, 3.3.0 to < 3.3.5, 3.4.0 to < 3.4.4
- Atlassian Crowd Data Center 2.1.0 to < 3.0.5, 3.1.0 to < 3.1.6, 3.2.0 to < 3.2.8, 3.3.0 to < 3.3.5, 3.4.0 to < 3.4.4
Timeline
- 2019-06-03: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild