LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-11580: Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-11580 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

CVE-2019-11580 is a remote code execution vulnerability in Atlassian Crowd and Crowd Data Center. It stems from a development plugin named pdkinstall that was incorrectly left enabled in release builds, giving attackers a path to run code on affected servers. This matters because Crowd often sits at the center of identity and access management; successful exploitation can lead to full server compromise and has been tied to ransomware activity. Confirm all version and patch details against the vendor advisory.

How it works

The core issue is that a plugin intended only for development remained active in production releases of Crowd and Crowd Data Center. When such a component is reachable, an unauthenticated or low-privilege attacker can abuse its installation or configuration interfaces to introduce and execute arbitrary code on the host. The result is remote code execution under the privileges of the Crowd process. Exact request formats and preconditions are not detailed here; treat any publicly exposed Crowd instance as potentially abusable until you verify it is patched and the plugin is disabled. Because the weakness is essentially an unintended attack surface left in a release build, the practical abuse path is straightforward once an attacker can reach the affected endpoint.

Am I affected? How to find it in your systems

Atlassian Crowd and Crowd Data Center are typically deployed as standalone identity servers or clustered data-center nodes that provide single sign-on, directory synchronization, and application access control. They commonly run on Linux or Windows hosts inside corporate networks or in cloud VPCs, often behind reverse proxies but sometimes exposed for remote authentication flows.

How to remediate

The primary action is to apply the updates published by Atlassian for Crowd and Crowd Data Center, following the vendor’s instructions exactly. CISA’s required action is the same: apply updates per vendor instructions. After patching:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

If your data may have been exposed

This vulnerability has been used in ransomware campaigns, so any unpatched Crowd instance that was reachable should be treated as potentially compromised. Isolate affected hosts, preserve volatile evidence, and begin incident-response procedures that include credential rotation, directory integrity checks, and review of downstream applications that trust Crowd for authentication. As a quick additional step, you can run a free exposure scan of your email addresses against known breach data sets to see whether related accounts already appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAtlassian · Crowd and Crowd Data Center
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities