CVE-2019-3395

CRITICAL

Atlassian Confluence <6.6.12, 6.13.0-6.13.3 - Server-Side Request Forgery via WebDAV Endpoint

Title source: llm
STIX 2.1

Description

The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.

References (1)

Core 1
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/CONFSERVER-57971

Scores

CVSS v3 9.8
EPSS 0.0804
EPSS Percentile 92.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-918
Status published
Products (2)
atlassian/confluence < 6.6.12
atlassian/confluence_server 6.13.0 - 6.13.3
Published Mar 25, 2019
Tracked Since Feb 18, 2026