EXPOSURES › CVE-2019-11580
CVE-2019-11580
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAtlassian's Crowd product shipped with a development plugin enabled, leading to remote code execution vulnerability actively exploited by ransomware actors.
A development plugin was mistakenly included in production builds of Atlassian Crowd, allowing for remote code execution. This is a significant risk for DIB organizations using Crowd, potentially leading to data breaches and compliance failures (NIST 800-171 controls 3.AO.1, 3.CP.1). Verify Crowd versions and promptly apply patches; consider compensating controls if patching is not immediately feasible.
Shame score — Shipping a product with a development plugin enabled in production demonstrates a serious lack of quality control and a failure to properly secure software, especially given its active exploitation by ransomware.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.