CVE-2019-11580
Summary
| CVE | CVE-2019-11580 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-03 14:29:00 UTC |
| Updated | 2022-04-19 15:36:00 UTC |
| Description | Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability. |
Risk And Classification
EPSS: 0.943830000 probability, percentile 0.999690000 (date 2026-04-02)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Known
Problem Types: NVD-CWE-noinfo
CISA Known Exploited Vulnerability
| Vendor | Atlassian |
|---|---|
| Product | Crowd and Crowd Data Center |
| Name | Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-11580 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [CWD-5388] Crowd - pdkinstall development plugin incorrectly enabled - CVE-2019-11580 - Create and track feature requests for Atlassian products. | MISC | jira.atlassian.com | Issue Tracking, Mitigation, Vendor Advisory |
| Atlassian Crowd pdkinstall Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Atlassian Crowd and Crowd Data Center CVE-2019-11580 Remote Code Execution Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.