CVE-2019-11580
Last modified
CVE-2019-11580 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. CISA has confirmed active exploitation in the wild. EPSS estimates a 95.36% chance of exploitation in the next 30 days.
Description
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Crowd | >= 2.1.0, < 3.0.5 |
| Atlassian | Crowd | >= 3.1.0, < 3.1.6 |
| Atlassian | Crowd | >= 3.2.0, < 3.2.8 |
| Atlassian | Crowd | >= 3.3.0, < 3.3.5 |
| Atlassian | Crowd | >= 3.4.0, < 3.4.4 |
References
- http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108637Broken Link
- https://jira.atlassian.com/browse/CWD-5388Issue Tracking, Mitigation, Vendor Advisory
- http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108637Broken Link
- https://jira.atlassian.com/browse/CWD-5388Issue Tracking, Mitigation, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11580US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2019-11580?
How severe is CVE-2019-11580?
How do I fix CVE-2019-11580?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-11574An issue was discovered in Simple Machines Forum (SMF) befor…9.8
- CVE-2019-11576Gitea before 1.8.0 allows 1FA for user accounts that have co…
- CVE-2019-11577dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_find…
- CVE-2019-11578auth.c in dhcpcd before 7.2.1 allowed attackers to infer sec…5.9
- CVE-2019-11579dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflo…5.3
- CVE-2019-1158An information disclosure vulnerability exists when the Wind…5.5
- CVE-2019-11581There was a server-side template injection vulnerability in …9.8
- CVE-2019-11582An argument injection vulnerability in Atlassian Sourcetree …
- CVE-2019-11583The issue searching component in Jira before version 8.1.0 a…
- CVE-2019-11584The MigratePriorityScheme resource in Jira before version 8.…
- CVE-2019-11585The startup.jsp resource in Jira before version 7.13.6, from…
- CVE-2019-11586The AddResolution.jspa resource in Jira before version 7.13.…
Are you affected by CVE-2019-11580?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
