ZeroHour

CVE-2019-11580

KEV ransomware PoC moderate

Unauthenticated RCE in Atlassian Crowd and Crowd Data Center

CISA: Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

Atlassian accidentally shipped its pdkinstall development plugin enabled in release builds of Crowd and Crowd Data Center, so anyone who can send requests to the instance can install arbitrary plugins on it. An unauthenticated attacker sends crafted requests to a vulnerable Crowd server, uploads a malicious plugin, and gains remote code execution on the host. All releases from 2.1.0 through the 3.4.x line are affected until the 3.0.5, 3.1.6, 3.2.8, 3.3.5, and 3.4.4 fixes, so essentially every Crowd deployment predating those patches is exposed, particularly enterprises using Crowd for centralized identity/SSO with the instance reachable over the network. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, a public PoC exploit is available, and EPSS assigns a 95.4% probability of exploitation within 30 days.

What to do: Upgrade Crowd or Crowd Data Center to 3.0.5, 3.1.6, 3.2.8, 3.3.5, or 3.4.4 (or later) on the corresponding release line; where patching is delayed, disable the pdkinstall plugin in the administration console as an interim mitigation. Review installed plugins for unfamiliar entries and hunt for web shells or post-exploitation activity, since CISA notes ransomware use of this flaw.

Affected
Atlassian Crowd2.1.0 before 3.0.5; 3.1.0 before 3.1.6; 3.2.0 before 3.2.8; 3.3.0 before 3.3.5; 3.4.0 before 3.4.4
Atlassian Crowd Data Center2.1.0 before 3.0.5; 3.1.0 before 3.1.6; 3.2.0 before 3.2.8; 3.3.0 before 3.3.5; 3.4.0 before 3.4.4
Estimated exposure
moderate≈ a few thousand internet-exposed Crowd/Crowd Data Center instances — Crowd is a niche enterprise identity/SSO product with an installed base far smaller than Jira or Confluence, and public internet scans and deployment patterns suggest only on the order of a few thousand exposed servers.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.

CISA Known Exploited Vulnerability
Affected
Atlassian Crowd and Crowd Data Center
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
atlassian
Products
crowd
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news