HTTP: Atlassian Crowd pdkinstall Plugin Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Atlassian Crowd. A successful attack can lead to arbitrary code execution.

Extended Description

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.

Affected Products

Atlassian crowd

References

BugTraq: 108637

CVE: CVE-2019-11580

Short Name
HTTP:CTS:ATLASSIAN-CROWD-PDK-CE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Atlassian CVE-2019-11580 Code Crowd Execution Plugin Remote bid:108637 pdkinstall
Release Date
12/11/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3485
False Positive
Unknown
Vendors

Atlassian

CVSS Score

7.5

Found a potential security threat?