Showing 12 vulnerabilities on this page for Confluence Server and Data Center

Signals CISA KEV Ransomware Nuclei
Atlassian vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Confluence Data Center and Server Remote Code Execution

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you

CWE-94May 21, 20241 related artifact
CVSS7.2v3.1EPSS88.3%PoCs6SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Atlassian Confluence Data Center and Server Template Injection Vulnerability

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect thei

CWE-74Jan 16, 20241 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs25SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites a

CWE-863Oct 31, 20231 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs10SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this

CWE-20Oct 4, 20231 related artifact
CVSS9.8v3.1EPSS99.2%PoCs33SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CWE-798Jul 20, 20221 related artifact
CVSS9.8v3.1EPSS98.2%PoCs4SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CWE-74CWE-917Jun 3, 20221 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs84SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

CWE-74CWE-917Aug 30, 20211 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs41SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Atlassian Confluence and Data Center Widget Connector Vulnerability

Atlassian Confluence and Data Center is vulnerable to a remote code execution vulnerability in the 'widget connector' component. The issue lies in a server-side template injection weakness.

Aug 17, 2021
CVSS-EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CWE-425CWE-862Aug 3, 20211 related artifact
CVSS5.3v3.1EPSS>99.9%PoCs3SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Atlassian Confluence Server and Data Center Server-Side Request Forgery (SSRF)

The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.

CWE-918Apr 1, 20211 related artifact
CVSS4.3v3.1EPSS38.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confl

CWE-22Apr 18, 20191 related artifact
CVSS8.8v3.1EPSS96.8%PoCs3SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

CWE-22Mar 25, 20191 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs23SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX