Show plain JSON{"id": "CVE-2019-11580", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}, {"type": "Secondary", "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2019-06-03T14:29:00.217", "references": [{"url": "http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.html", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "source": "security@atlassian.com"}, {"url": "http://www.securityfocus.com/bid/108637", "tags": ["Broken Link"], "source": "security@atlassian.com"}, {"url": "https://jira.atlassian.com/browse/CWD-5388", "tags": ["Issue Tracking", "Mitigation", "Vendor Advisory"], "source": "security@atlassian.com"}, {"url": "http://packetstormsecurity.com/files/163810/Atlassian-Crowd-pdkinstall-Remote-Code-Execution.html", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/108637", "tags": ["Broken Link"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://jira.atlassian.com/browse/CWD-5388", "tags": ["Issue Tracking", "Mitigation", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability."}, {"lang": "es", "value": "Atlassian Crowd and Crowd Data Center ten\u00eda el complemento de desarrollo pdkinstall habilitado incorrectamente en las versiones de lanzamiento. Los atacantes que pueden enviar solicitudes no Identificadas o identificadas a una instancia de Crowd o Crowd Data Center pueden aprovechar esta vulnerabilidad para instalar complementos arbitrarios, que permiten la ejecuci\u00f3n remota de c\u00f3digo en sistemas que ejecutan una versi\u00f3n vulnerable de Crowd o Crowd Data Center. Todas las versiones de Crowd desde la versi\u00f3n 2.1.0 antes de 3.0.5 (la versi\u00f3n fija para 3.0.x), desde la versi\u00f3n 3.1.0 antes de 3.1.6 (la versi\u00f3n fija para 3.1.x), desde la versi\u00f3n 3.2.0 antes de 3.2. 8 (la versi\u00f3n fija para 3.2.x), desde la versi\u00f3n 3.3.0 antes de 3.3.5 (la versi\u00f3n fija para 3.3.x), y desde la versi\u00f3n 3.4.0 antes de 3.4.4 (la versi\u00f3n fija para 3.4.x) son afectados por esta vulnerabilidad."}], "lastModified": "2025-03-14T14:54:03.240", "cisaActionDue": "2022-05-03", "cisaExploitAdd": "2021-11-03", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A1ACCE0-62AA-4F7A-B854-62AF37711578", "versionEndExcluding": "3.0.5", "versionStartIncluding": "2.1.0"}, {"criteria": "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "145C1D3C-8086-4060-A750-1CB62008E7C4", "versionEndExcluding": "3.1.6", "versionStartIncluding": "3.1.0"}, {"criteria": "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AEF87FBF-5F7F-44EC-A298-D2A98B3FE7BB", "versionEndExcluding": "3.2.8", "versionStartIncluding": "3.2.0"}, {"criteria": "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B11C64A2-460A-4FEB-89C0-E459569A8F94", "versionEndExcluding": "3.3.5", "versionStartIncluding": "3.3.0"}, {"criteria": "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD8E1AB0-9141-4AD0-9B0B-8B61EE185267", "versionEndExcluding": "3.4.4", "versionStartIncluding": "3.4.0"}], "operator": "OR"}]}], "sourceIdentifier": "security@atlassian.com", "cisaRequiredAction": "Apply updates per vendor instructions.", "cisaVulnerabilityName": "Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability"}