CVE-2021-26084
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-917
מוצרים מושפעים
atlassian: confluence data center; atlassian: confluence server
קישורים
- https://jira.atlassian.com/browse/CONFSERVER-67940 Issue TrackingPatchVendor Advisory
- https://jira.atlassian.com/browse/CONFSERVER-67940 Issue TrackingPatchVendor Advisory
- http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGN… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGN… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource