AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9536 99.9 YES
AFFECTED Product Versions Fixed Crowd 2.1.0 – —
TIMELINE Apr 29 Reserved by atlassian Jun 3 Published (CNA: atlassian) Nov 3 Added to CISA KEV, remediation due 2022-05-03
Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9536 99.9 YES
AFFECTED Product Versions Fixed Crowd 2.1.0 – —
TIMELINE Apr 29 Reserved by atlassian Jun 3 Published (CNA: atlassian) Nov 3 Added to CISA KEV, remediation due 2022-05-03
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.
| Date | Event | Detail |
|---|---|---|
| April 29, 2019 | Reserved | Reserved by atlassian |
| June 3, 2019 | Published | Published (CNA: atlassian) |
| November 3, 2021 | KEV ADDED | Added to CISA KEV, remediation due 2022-05-03 |
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
|---|---|---|---|---|
| Atlassian | Crowd | — | 2.1.0 | — |
Authoritative record: CVE-2019-11580 at cve.org
Vendors: atlassian
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2019-11580 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Tuesday, October 6, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.