Junglewise Threat Intelligence

CVE-2019-3398: Atlassian Confluence Server and Data Center Path Traversal Vulnerability

CVE-2019-3398 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Atlassian Data Center, Atlassian Confluence Data Center, Atlassian Confluence Server. Vendors: Atlassian.

Executive brief

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource. A remote attacker with specific permissions (such as adding attachments or space administration) can exploit this to write files to arbitrary locations, potentially leading to remote code execution.

Affected products

  • Atlassian Confluence Server 2.0.0 to < 6.6.13, 6.7.0 to < 6.12.4, 6.13.0 to < 6.13.4, 6.14.0 to < 6.14.3, 6.15.0 to < 6.15.2
  • Atlassian Confluence Data Center 2.0.0 to < 6.6.13, 6.7.0 to < 6.12.4, 6.13.0 to < 6.13.4, 6.14.0 to < 6.14.3, 6.15.0 to < 6.15.2

Timeline

  • 2019-04-17: disclosed: Initial public disclosure and bugtraq mailing list entry
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog

Related threats