CVE-2019-3398
Summary
| CVE | CVE-2019-3398 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-18 18:29:00 UTC |
| Updated | 2022-04-12 18:39:00 UTC |
| Description | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability. |
Risk And Classification
EPSS: 0.971530000 probability, percentile 0.998870000 (date 2026-07-21)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Unknown
Problem Types: CWE-22
CISA Known Exploited Vulnerability
| Vendor | Atlassian |
|---|---|
| Product | Confluence Server and Data Center |
| Name | Atlassian Confluence Server and Data Center Path Traversal Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-3398 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Confluence | All | All | All | All |
| Application | Atlassian | Confluence | All | All | All | All |
| Application | Atlassian | Confluence Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Confluence Server / Data Center Path Traversal ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| [CONFSERVER-58102] Confluence - Path traversal vulnerability - CVE-2019-3398 - Create and track feature requests for Atlassian products. | MISC | jira.atlassian.com | Issue Tracking, Patch, Vendor Advisory |
| Atlassian Confluence Server and Confluence Data Center Directory Traversal Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Atlassian Confluence 6.15.1 Directory Traversal ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Atlassian Confluence 6.15.1 Directory Traversal ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Bugtraq: Confluence Security Advisory - 2019-04-17 | BUGTRAQ | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.