CVE-2019-11580
Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.8
- EPSS
- 95.4% 백분위 99.9% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.05.03
- 공개일
- 2019.06.03
CISA KEV에 등록된 실제 악용 확인 취약점
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x...
공급사 Atlassian
제품 Crowd and Crowd Data Center
영향 버전 2.1.0, unspecified, 3.1.0, 3.2.0, 3.3.0, 3.4.0, >= 2.1.0 < 3.0.5, >= 3.1.0 < 3.1.6, >= 3.2.0 < 3.2.8, >= 3.3.0 < 3.3.5, >= 3.4.0 < 3.4.4
수정 버전 3.0.5, 3.1.6, 3.2.8, 3.3.5, 3.4.4
Apply updates per vendor instructions.
조치 기한: 2022.05.03CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE 미등록
KEV 등록일 2021.11.03
랜섬웨어 캠페인 사용 확인됨
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2019-11580
EPSS 데이터 기준일 2026.06.27