Showing 7 vulnerabilities on this page for Confluence

Signals CISA KEV Ransomware Nuclei
Atlassian vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CWE-798Jul 20, 20221 related artifact
CVSS9.8v3.1EPSS98.2%PoCs4SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confl

CWE-22Apr 18, 20191 related artifact
CVSS8.8v3.1EPSS96.8%PoCs3SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.

CWE-20Jul 10, 2018
CVSS4.7v3.0EPSS0.998%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.

CWE-79Feb 2, 2018
CVSS4.8v3.0EPSS0.601%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.

CWE-79Feb 2, 2018
CVSS6.1v3.0EPSS0.809%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.

CWE-79Feb 2, 2018
CVSS5.4v3.0EPSS0.58%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.

CWE-79Dec 5, 2017
CVSS6.1v3.0EPSS0.809%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX