CVE-2019-3396
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-22
מוצרים מושפעים
atlassian: confluence server
קישורים
- https://jira.atlassian.com/browse/CONFSERVER-57974 Issue TrackingPatchVendor Advisory
- https://jira.atlassian.com/browse/CONFSERVER-57974 Issue TrackingPatchVendor Advisory
- http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connec… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161065/Atlassian-Confluence-6.12.1-Templa… ExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connector ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46731/ ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connec… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161065/Atlassian-Confluence-6.12.1-Templa… ExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connector ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46731/ ExploitThird Party AdvisoryVDB Entry