QID 730542

Date Published: 2022-07-05

QID 730542: Atlassian Confluence Server and Confluence Data Center Log4j Multiple Vulnerabilities (CONFSERVER-78991)

Confluence is team collaboration software written in Java.



Affected version:
Confluence Server and Data Center versions
Versions prior to 7.4.17
All versions 7.5.x through 7.12.x
Versions prior to 7.13.6
Versions prior to 7.14.3
Versions prior to 7.15.2
Versions prior to 7.16.4
Versions prior to 7.17.2 are affected

QID Detection Logic:(Unauthenticated)
It checks for vulnerable versions of Atlassian Confluence Server.

Successful exploitation of this vulnerability could lead to a security breach or could affect confidentiality, integrity, and availability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to refer to CONFSERVER-78991 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 730542

    Software Advisories
    Advisory ID Software Component Link
    CONFSERVER-78991 URL Logo jira.atlassian.com/browse/CONFSERVER-78991