QID 730425

Date Published: 2022-04-07

QID 730425: Atlassian Confluence Data Center Remote Code Execution (RCE) Vulnerability

Confluence Data Center is a self-managed solution that provides you with the additional configuration options you need to meet the collaboration needs of the most demanding teams.

Confluence Data Center.

Affected Versions:
All versions 5.6.x and later
QID Detection Logic(Unauthenticated):
It checks for vulnerable version of Atlassian Confluence using GET request to login.action page.

A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted JoinRequest, resulting in arbitrary code execution.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    For more information please visit Confluence Security Advisory for remediation of this vulnerability.

    Workaround:
    Confluence Data Center is only affected when it is installed as a cluster. To verify whether a cluster installation is being used, check the confluence.cfg.xml file in the Confluence home directory. If the following line is present, it has been installed as a cluster: <PROPERTY NAME="confluence.cluster">true</PROPERTY> If the line is not present or if the value is set to false instead of true, it has not been installed as a cluster. Restrict access to the Hazelcast port by using a firewall or other network access controls. The port only needs to be accessible by other nodes in the Confluence. For Confluence Data Center, Hazelcast uses both TCP ports 5701 and 5801 by default.

    CVEs related to QID 730425

    Software Advisories
    Advisory ID Software Component Link
    CVE-2016-10750 URL Logo confluence.atlassian.com/security/multiple-products-security-advisory-hazelcast-vulnerable-to-remote-code-execution-cve-2016-10750-1116292387.html?utm_source=alert-email&utm_medium=email&utm_campaign=bitbucket-data-center-confluence-data-center-security-advisory-march_EML-12770&jobid=105489999&subid=1544944158

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report