PT-2024-2835 · Atlassian · Confluence
Published
2024-04-16
·
Updated
2024-04-18
·
CVE-2024-21676
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Confluence Data Center versions 7.3.0 through 8.5.7
Description
The issue exists due to the failure to neutralize special elements used in operating system commands. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information by modifying system calls.
Recommendations
For Confluence Data Center versions 7.3.0 through 8.5.7, upgrade to a release greater than or equal to 8.5.8.
As a temporary workaround, consider restricting system call modifications until a patch is available.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Confluence