#VU18716 Exposed dangerous method or function in Crowd Server - CVE-2019-11580
Published: June 7, 2019 / Updated: August 12, 2021
Crowd Server
Atlassian
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to incorrectly enabled pdkinstall development plugin in release builds. A remote unauthenticated attacker can install arbitrary plugin and gain full control over the affected system.
Successful exploitation of the vulnerability may allow remote code execution.