Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11580

Опубликовано: 03 июн. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Критический

Описание

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
Версия от 2.1.0 (включая) до 3.0.5 (исключая)
cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
Версия от 3.1.0 (включая) до 3.1.6 (исключая)
cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
Версия от 3.2.0 (включая) до 3.2.8 (исключая)
cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
Версия от 3.3.0 (включая) до 3.3.5 (исключая)
cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
Версия от 3.4.0 (включая) до 3.4.4 (исключая)

EPSS

Процентиль: 100%
0.94386
Критический

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.

CVSS3: 9.8
fstec
почти 7 лет назад

Уязвимость плагина pdkinstall системы аутентификации и управления пользователями Atlassian Crowd, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.94386
Критический

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo