PT-2024-1277 · Atlassian · Confluence

Xiaoc

·

Published

2024-01-15

·

Updated

2024-01-22

·

CVE-2024-21673

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Confluence Data Center and Server versions 7.13.0 through 7.19.17 Confluence Data Center and Server versions 8.5.0 through 8.5.4 Confluence Data Center and Server versions 8.7.0 through 8.7.1
Description The vulnerability is related to insufficient input validation, allowing a remote attacker to execute arbitrary code. This issue has a high impact on confidentiality, integrity, and availability, and does not require user interaction.
Recommendations For Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release For Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release For Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00703
CVE-2024-21673

Affected Products

Confluence