CVE-2019-11580

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.

References

https://jira.atlassian.com/browse/CWD-5388

http://www.securityfocus.com/bid/108637

http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.html

Details

Source: MITRE

Published: 2019-06-03

Updated: 2021-08-12

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (8 total)

IDNameProductFamilySeverity
138553Atlassian Crowd 2.1.x < 3.0.5 / 3.1.x < 3.1.6 / 3.2.x < 3.2.8 / 3.3.x < 3.3.5 / 3.4.x < 3.4.4 RCE (direct check)NessusCGI abuses
critical
98660Atlassian Crowd 2.1.x < 3.0.5 RCE VulnerabilityWeb Application ScanningComponent Vulnerability
critical
98659Atlassian Crowd 3.1.x < 3.1.6 RCE VulnerabilityWeb Application ScanningComponent Vulnerability
critical
98658Atlassian Crowd 3.2.x < 3.2.8 RCE VulnerabilityWeb Application ScanningComponent Vulnerability
critical
98657Atlassian Crowd 3.3.x < 3.3.5 RCE VulnerabilityWeb Application ScanningComponent Vulnerability
critical
98656Atlassian Crowd 3.4.x < 3.4.4 RCE VulnerabilityWeb Application ScanningComponent Vulnerability
critical
701078Atlassian Crowd 2.1.x < 3.0.5 / 3.1.x < 3.1.6 / 3.2.x < 3.2.8 / 3.3.x < 3.3.5 / 3.4.x < 3.4.4 RCENessus Network MonitorCGI
critical
125477Atlassian Crowd 2.1.x < 3.0.5 / 3.1.x < 3.1.6 / 3.2.x < 3.2.8 / 3.3.x < 3.3.5 / 3.4.x < 3.4.4 RCE VulnerabilityNessusCGI abuses
critical