CVE-2019-3398
HIGH KEV NUCLEIConfluence Server 6.15.1 - Path Traversal and Remote Code Execution
Title source: llmExploitation Summary
CVE-2019-3398 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 3 public exploits from researchers including max7253, superevr, 132231g. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability (CVE-2019-3398) in Atlassian Confluence 6.15.1 to achieve arbitrary file write, allowing an attacker to upload a webshell. It authenticates, retrieves an Atlassian token, and exploits the path traversal to place the shell in the web root.
Description
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.
Exploits (3)
This exploit leverages a directory traversal vulnerability (CVE-2019-3398) in Atlassian Confluence 6.15.1 to achieve arbitrary file write, allowing an attacker to upload a webshell. It authenticates, retrieves an Atlassian token, and exploits the path traversal to place the shell in the web root.
This PoC exploits CVE-2019-3398 in Atlassian Confluence by uploading a malicious JSP shell via a path traversal vulnerability in the drag-and-drop upload feature. It requires valid credentials and leverages a CSRF token to bypass protections.
This YAML-based PoC for CVE-2019-3398 exploits a directory traversal vulnerability in Confluence to upload a JSP shell. It includes authentication, token extraction, and multi-step exploitation to achieve remote code execution.
Nuclei Templates (1)
http.component:"atlassian confluence" || cpe:"cpe:2.3:a:atlassian:confluence"
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H