CISA Known Exploited Vulnerability

CVE-2019-11580 Ransomware

Atlassian · Crowd and Crowd Data Center

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Known

CISA description

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

Required action

Apply updates per vendor instructions.