CVE-2019-11580

Confirmed PUBLISHED

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send...

Atlassian · Crowd
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 95.4%

At a Glance

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.

cisa metasploit nuclei_scanner malware
CVE Published
Jun 03, 2019
Exploitation Reported
Nov 03, 2021
CVSS
9.8 Critical
EPSS
95.4%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Atlassian
Crowd

2.1.0 to < unspecified

Affected
Atlassian
Crowd

unspecified to < 3.0.5

Affected
Atlassian
Crowd

3.1.0 to < unspecified

Affected
Atlassian
Crowd

unspecified to < 3.1.6

Affected
Atlassian
Crowd

3.2.0 to < unspecified

Affected
Atlassian
Crowd

unspecified to < 3.2.8

Affected
Atlassian
Crowd

3.3.0 to < unspecified

Affected
Atlassian
Crowd

unspecified to < 3.3.5

Affected
Atlassian
Crowd

3.4.0 to < unspecified

Affected
Atlassian
Crowd

unspecified to < 3.4.4

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.