CVE-2019-11580
KEV ransomware PoC moderateUnauthenticated RCE in Atlassian Crowd and Crowd Data Center
CISA: Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability
Atlassian accidentally shipped its pdkinstall development plugin enabled in release builds of Crowd and Crowd Data Center, so anyone who can send requests to the instance can install arbitrary plugins on it. An unauthenticated attacker sends crafted requests to a vulnerable Crowd server, uploads a malicious plugin, and gains remote code execution on the host. All releases from 2.1.0 through the 3.4.x line are affected until the 3.0.5, 3.1.6, 3.2.8, 3.3.5, and 3.4.4 fixes, so essentially every Crowd deployment predating those patches is exposed, particularly enterprises using Crowd for centralized identity/SSO with the instance reachable over the network. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, a public PoC exploit is available, and EPSS assigns a 95.4% probability of exploitation within 30 days.
What to do: Upgrade Crowd or Crowd Data Center to 3.0.5, 3.1.6, 3.2.8, 3.3.5, or 3.4.4 (or later) on the corresponding release line; where patching is delayed, disable the pdkinstall plugin in the administration console as an interim mitigation. Review installed plugins for unfamiliar entries and hunt for web shells or post-exploitation activity, since CISA notes ransomware use of this flaw.
| Atlassian Crowd | 2.1.0 before 3.0.5; 3.1.0 before 3.1.6; 3.2.0 before 3.2.8; 3.3.0 before 3.3.5; 3.4.0 before 3.4.4 |
| Atlassian Crowd Data Center | 2.1.0 before 3.0.5; 3.1.0 before 3.1.6; 3.2.0 before 3.2.8; 3.3.0 before 3.3.5; 3.4.0 before 3.4.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.
- Affected
- Atlassian Crowd and Crowd Data Center
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- atlassian
- Products
- crowd
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H