Executive brief
The Widget Connector macro in Atlassian Confluence Server and Data Center contains a server-side template injection vulnerability. Remote attackers can exploit this to achieve path traversal and remote code execution on the affected instance.
Affected products
- Atlassian Confluence Server < 6.6.12, 6.7.0 to < 6.12.3, 6.13.0 to < 6.13.3, 6.14.0 to < 6.14.2
- Atlassian Confluence Data Center < 6.6.12, 6.7.0 to < 6.12.3, 6.13.0 to < 6.13.3, 6.14.0 to < 6.14.2
Timeline
- 2019-03-20: advisory: Initial vendor advisory (CONFSERVER-57974) published
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed: NVD publication date