Junglewise Threat Intelligence

CVE-2019-3396: Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

CVE-2019-3396 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Atlassian Confluence Data Center, Atlassian Confluence Server. Vendors: Atlassian.

Executive brief

The Widget Connector macro in Atlassian Confluence Server and Data Center contains a server-side template injection vulnerability. Remote attackers can exploit this to achieve path traversal and remote code execution on the affected instance.

Affected products

  • Atlassian Confluence Server < 6.6.12, 6.7.0 to < 6.12.3, 6.13.0 to < 6.13.3, 6.14.0 to < 6.14.2
  • Atlassian Confluence Data Center < 6.6.12, 6.7.0 to < 6.12.3, 6.13.0 to < 6.13.3, 6.14.0 to < 6.14.2

Timeline

  • 2019-03-20: advisory: Initial vendor advisory (CONFSERVER-57974) published
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: NVD publication date

Related threats