CVE-2019-3395
CRITICALAtlassian Confluence <6.6.12, 6.13.0-6.13.3 - Server-Side Request Forgery via WebDAV Endpoint
Title source: llmDescription
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.
References (1)
Core 1
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/CONFSERVER-57971
Scores
CVSS v3
9.8
EPSS
0.0804
EPSS Percentile
92.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-918
Status
published
Products (2)
atlassian/confluence
< 6.6.12
atlassian/confluence_server
6.13.0 - 6.13.3
Published
Mar 25, 2019
Tracked Since
Feb 18, 2026