HIGH🇬🇧 English

CVE-2024-21683

CVSS 8.8v3.1pub. 2024-05-21upd. 2025-05-12

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html You can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives. This vulnerability was found internally.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Atlassian Confluence Data Center

    APP
    Atlassian
    8.7.18.7.28.8.08.8.18.6.0 – 8.6.28.9.0 – 8.9.3 (bez)8.3.0 – 8.3.47.19.0 – 7.19.24 (bez)8.4.0 – 8.4.58.5.0 – 8.5.11 (bez)7.20.0 – 7.20.38.0.0 – 8.0.48.1.0 – 8.1.48.2.0 – 8.2.3
  • Atlassian Confluence Server

    APP
    Atlassian
    8.7.18.7.28.8.08.8.18.3.0 – 8.3.47.19.0 – 7.19.24 (bez)7.20.0 – 7.20.38.0.0 – 8.0.48.1.0 – 8.1.48.2.0 – 8.2.38.4.0 – 8.4.58.5.0 – 8.5.11 (bez)8.6.0 – 8.6.28.9.0 – 8.9.2
  • Atlassian Crucible

    APP
    Atlassian
    4.8.0 – 4.8.15 (bez)
  • Atlassian Fisheye

    APP
    Atlassian
    4.8.0 – 4.8.15 (bez)
  • Atlassian Jira Data Center

    APP
    Atlassian
    9.4.0 – 9.4.21 (bez)9.12.0 – 9.12.8 (bez)
  • Atlassian Jira Server

    APP
    Atlassian
    9.12.0 – 9.12.8 (bez)9.4.0 – 9.4.21 (bez)
  • Atlassian Jira Service Management

    APP
    Atlassian
    5.15.25.4.0 – 5.4.21 (bez)5.12.0 – 5.12.8 (bez)5.15.2 – 5.16.0 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Referencje

Powiązane podatności

CVE-2023-22527CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE via template injection w Atlassian Confluence Data Center i Server

CVE-2023-22518CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Atlassian Confluence – Improper Authorization umożliwia przejęcie instancji

CVE-2023-22515CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Atlassian Confluence – nieautoryzowane tworzenie kont administratora

CVE-2022-26138CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Atlassian Questions For Confluence — ukryte konto z hardcoded hasłem

CVE-2022-26134CRITICAL9.8⚠ KEVPL ✓ten sam produkt

OGNL Injection RCE w Atlassian Confluence Server i Data Center