Executive brief
Atlassian Confluence Server and Data Center are vulnerable to an Object-Graph Navigation Language (OGNL) injection. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code on the affected instance.
Affected products
- Atlassian Confluence Server before 6.13.23, 6.14.0 to 7.4.11, 7.5.0 to 7.11.6, 7.12.0 to 7.12.5
- Atlassian Confluence Data Center before 6.13.23, 6.14.0 to 7.4.11, 7.5.0 to 7.11.6, 7.12.0 to 7.12.5
Timeline
- 2021-11-03: disclosed: Vulnerability published and added to CISA KEV catalog.
- 2021-11-03: kev added
- 2021-11-03: exploited: Reported as exploited in the wild.