Atlassian Vulnerabilities and Affected Products
Vulnerabilities associated with Confluence.
Products
Clear product- Jira Server99 vulnerabilities
- Jira Data Center64 vulnerabilities
- Jira52 vulnerabilities
- Confluence Server38 vulnerabilities
- Confluence Data Center35 vulnerabilities
- Crucible29 vulnerabilities
- Fisheye27 vulnerabilities
- jira_data_center26 vulnerabilities
- jira_server25 vulnerabilities
- Jira Server and Data Center21 vulnerabilities
- Bitbucket Server18 vulnerabilities
- Crowd16 vulnerabilities
- Fisheye and Crucible16 vulnerabilities
- Bamboo15 vulnerabilities
- Jira Service Management Data Center14 vulnerabilities
- Bitbucket Data Center13 vulnerabilities
- Jira Align13 vulnerabilities
- Jira Service Management Server13 vulnerabilities
- Confluence Server and Data Center12 vulnerabilities
- confluence_data_center12 vulnerabilities
- confluence_server10 vulnerabilities
- Bamboo Data Center8 vulnerabilities
- Sourcetree for Windows8 vulnerabilities
- Confluence7 vulnerabilities
- Bamboo Server6 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-26138CRITICAL | Atlassian Questions For Confluence App Hard-coded Credentials VulnerabilityThe Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app. | CVSS9.8v3.1 | EPSS98.2% | PoCs4 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2019-3398HIGH | Atlassian Confluence Server and Data Center Path Traversal VulnerabilityConfluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confl… | CVSS8.8v3.1 | EPSS96.8% | PoCs3 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-13389MEDIUM | The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml. CWE-20Jul 10, 2018 | CVSS4.7v3.0 | EPSS0.998% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-18084MEDIUM | The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro. CWE-79Feb 2, 2018 | CVSS4.8v3.0 | EPSS0.601% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-18085MEDIUM | The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. CWE-79Feb 2, 2018 | CVSS6.1v3.0 | EPSS0.809% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-18083MEDIUM | The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file. CWE-79Feb 2, 2018 | CVSS5.4v3.0 | EPSS0.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-16856MEDIUM | The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme. CWE-79Dec 5, 2017 | CVSS6.1v3.0 | EPSS0.809% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |