QID 731082

Date Published: 2024-01-22

QID 731082: Atlassian Confluence Data Center and Server Multiple Vulnerabilities (CONFSERVER-94064,CONFSERVER-94065)

Atlassian Confluence is team collaboration software written in Java.

A template injection vulnerability on out-of-date versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected version. Customers using an affected version must take immediate action.

Affected products:
Confluence Data Center and Confluence Server

Affected version:
Confluence data center and server versions: From version 1.0.0, 7.13.0, 7.19.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1

QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Confluence Server.

Successful exploitation of this vulnerability could lead to a security breach or could affect confidentiality, integrity, and availability.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to refer to CONFSERVER-94064 for updates pertaining to this vulnerability.
    Customers are advised to refer to CONFSERVER-94065 for updates pertaining to this vulnerability.

    CVEs related to QID 731082

    Software Advisories
    Advisory ID Software Component Link
    CONFSERVER-94064 URL Logo jira.atlassian.com/browse/CONFSERVER-94064
    CONFSERVER-94065 URL Logo jira.atlassian.com/browse/CONFSERVER-94065