⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2022-05-03.

CVE-2019-11580

9 documents9 sources
Severity
9.8CRITICAL
EPSS
94.4%
top 0.03%
CISA KEV
KEVRansomware
Added 2021-11-03
Due 2022-05-03
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJun 3
KEV addedNov 3
KEV dueMay 3
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5atlassian/crowd2.1.0unspecified+9
NVDatlassian/crowd2.1.03.0.5+4

🔴Vulnerability Details

3
GHSA
GHSA-8977-4jwc-24g8: Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds2022-05-24
CVEList
CVE-2019-11580: Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds2019-06-03
VulnCheck
Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability2019

💥Exploits & PoCs

1
Nuclei
Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Atlassian Crowd Plugin Upload Attempt (CVE-2019-11580)2019-07-16

📋Vendor Advisories

1
CISA
Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability2021-11-03

💬Community

1
HackerOne
Root Remote Code Execution on https://███2019-10-04