Executive brief
Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource. A remote attacker with specific permissions (such as adding attachments or space administration) can exploit this to write files to arbitrary locations, potentially leading to remote code execution.
Affected products
- Atlassian Confluence Server 2.0.0 to < 6.6.13, 6.7.0 to < 6.12.4, 6.13.0 to < 6.13.4, 6.14.0 to < 6.14.3, 6.15.0 to < 6.15.2
- Atlassian Confluence Data Center 2.0.0 to < 6.6.13, 6.7.0 to < 6.12.4, 6.13.0 to < 6.13.4, 6.14.0 to < 6.14.3, 6.15.0 to < 6.15.2
Timeline
- 2019-04-17: disclosed: Initial public disclosure and bugtraq mailing list entry
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog