HIGH🇵🇱 Wersja polska

CVE-2024-21683

CVSS 8.8v3.1pub. 2024-05-21upd. 2025-05-12

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html You can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives. This vulnerability was found internally.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Atlassian Confluence Data Center

    APP
    Atlassian
    8.7.18.7.28.8.08.8.18.6.0 – 8.6.28.9.0 – 8.9.3 (excl.)8.3.0 – 8.3.47.19.0 – 7.19.24 (excl.)8.4.0 – 8.4.58.5.0 – 8.5.11 (excl.)7.20.0 – 7.20.38.0.0 – 8.0.48.1.0 – 8.1.48.2.0 – 8.2.3
  • Atlassian Confluence Server

    APP
    Atlassian
    8.7.18.7.28.8.08.8.18.3.0 – 8.3.47.19.0 – 7.19.24 (excl.)7.20.0 – 7.20.38.0.0 – 8.0.48.1.0 – 8.1.48.2.0 – 8.2.38.4.0 – 8.4.58.5.0 – 8.5.11 (excl.)8.6.0 – 8.6.28.9.0 – 8.9.2
  • Atlassian Crucible

    APP
    Atlassian
    4.8.0 – 4.8.15 (excl.)
  • Atlassian Fisheye

    APP
    Atlassian
    4.8.0 – 4.8.15 (excl.)
  • Atlassian Jira Data Center

    APP
    Atlassian
    9.4.0 – 9.4.21 (excl.)9.12.0 – 9.12.8 (excl.)
  • Atlassian Jira Server

    APP
    Atlassian
    9.12.0 – 9.12.8 (excl.)9.4.0 – 9.4.21 (excl.)
  • Atlassian Jira Service Management

    APP
    Atlassian
    5.15.25.4.0 – 5.4.21 (excl.)5.12.0 – 5.12.8 (excl.)5.15.2 – 5.16.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2023-22527CRITICAL9.8⚠ KEVPL ✓same product

RCE via template injection w Atlassian Confluence Data Center i Server

CVE-2023-22518CRITICAL9.8⚠ KEVPL ✓same product

Atlassian Confluence – Improper Authorization umożliwia przejęcie instancji

CVE-2023-22515CRITICAL9.8⚠ KEVPL ✓same product

Atlassian Confluence – nieautoryzowane tworzenie kont administratora

CVE-2022-26138CRITICAL9.8⚠ KEVPL ✓same product

Atlassian Questions For Confluence — ukryte konto z hardcoded hasłem

CVE-2022-26134CRITICAL9.8⚠ KEVPL ✓same product

OGNL Injection RCE w Atlassian Confluence Server i Data Center