CVE-2019-3396
Summary
| CVE | CVE-2019-3396 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-25 19:29:00 UTC |
| Updated | 2021-12-13 16:05:00 UTC |
| Description | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection. |
Risk And Classification
EPSS: 0.999130000 probability, percentile 0.999670000 (date 2026-07-21)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Known
Problem Types: CWE-22
CISA Known Exploited Vulnerability
| Vendor | Atlassian |
|---|---|
| Product | Confluence Server and Data Server |
| Name | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-3396 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Confluence | All | All | All | All |
| Application | Atlassian | Confluence | All | All | All | All |
| Application | Atlassian | Confluence Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit) - Multiple remote Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Atlassian Confluence Widget Connector Macro Velocity Template Injection | MISC | www.rapid7.com | Exploit, Third Party Advisory, VDB Entry |
| [CONFSERVER-57974] Remote code execution via Widget Connector macro - CVE-2019-3396 - Create and track feature requests for Atlassian products. | MISC | jira.atlassian.com | Issue Tracking, Patch, Vendor Advisory |
| Atlassian Confluence Widget Connector Macro Velocity Template Injection ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Atlassian Confluence 6.12.1 Template Injection ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.