[{"advisory":{"name":"Confluence Security Advisory - 2019-12-18","url":"https://confluence.atlassian.com/doc/confluence-security-advisory-2019-12-18-982324349.html"},"cveId":"CVE-2019-15006","description":"There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Previews plugin in Confluence Server and Confluence Data Center communicated with the Companion application via the atlassian-domain-for-localhost-connections-only.com domain name, the DNS A record of which points at 127.0.0.1. Additionally, a signed certificate for the domain was publicly distributed with the Companion application. An attacker in the position to control DNS resolution of their victim could carry out a man-in-the-middle (MITM) attack between Confluence Server (or Confluence Data Center) and the atlassian-domain-for-localhost-connections-only.com domain intended to be used with the Companion application. This certificate has been revoked, however, usage of the atlassian-domain-for-localhost-connections-only.com domain name was still present in Confluence Server and Confluence Data Center. An attacker could perform the described attack by denying their victim access to certificate revocation information, and carry out a man-in-the-middle (MITM) attack to observe files being edited using the Companion application and/or modify them, and access some limited user information.","baseScore":6.5,"cpeMatches":[{"versionStartIncluding":"6.11.0","versionEndExcluding":"6.13.10"},{"versionStartIncluding":"6.14.0","versionEndExcluding":"6.15.10"},{"versionStartIncluding":"7.0.1","versionEndExcluding":"7.0.5"},{"versionStartIncluding":"7.1.0","versionEndExcluding":"7.1.2"}]},{"advisory":{"name":"Confluence Security Advisory - 2019-08-28","url":"https://confluence.atlassian.com/x/uAsvOg"},"cveId":"CVE-2019-3394","description":"There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting. An attacker with permission to editing a page is able to exploit this issue to read arbitrary file on the server under <install-directory>/confluence/WEB-INF directory, which may contain configuration files used for integrating with other services, which could potentially leak credentials or other sensitive information such as LDAP credentials. The LDAP credential will be potentially leaked only if the Confluence server is configured to use LDAP as user repository. All versions of Confluence Server from 6.1.0 before 6.6.16 (the fixed version for 6.6.x), from 6.7.0 before 6.13.7 (the fixed version for 6.13.x), and from 6.14.0 before 6.15.8 (the fixed version for 6.15.x) are affected by this vulnerability.","baseScore":8.8,"cpeMatches":[{"versionStartIncluding":"6.1.0","versionEndExcluding":"6.6.16"},{"versionStartIncluding":"6.7.0","versionEndExcluding":"6.13.7"},{"versionStartIncluding":"6.14.0","versionEndExcluding":"6.15.8"}]},{"advisory":{"name":"Confluence Security Advisory - 2019-03-20","url":"https://confluence.atlassian.com/doc/confluence-security-advisory-2019-03-20-966660264.html"},"cveId":"CVE-2019-3395","description":"The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"6.6.12"},{"versionStartIncluding":"6.7.0","versionEndExcluding":"6.12.3"},{"versionStartIncluding":"6.13.0","versionEndExcluding":"6.13.3"},{"versionStartIncluding":"6.14.0","versionEndExcluding":"6.14.2"}]},{"advisory":{"name":"Confluence Security Advisory - 2019-03-20","url":"https://confluence.atlassian.com/doc/confluence-security-advisory-2019-03-20-966660264.html"},"cveId":"CVE-2019-3396","description":"The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"6.6.12"},{"versionStartIncluding":"6.7.0","versionEndExcluding":"6.12.3"},{"versionStartIncluding":"6.13.0","versionEndExcluding":"6.13.3"},{"versionStartIncluding":"6.14.0","versionEndExcluding":"6.14.2"}]},{"advisory":{"name":"Confluence Security Advisory - 2019-04-17","url":"https://confluence.atlassian.com/doc/confluence-security-advisory-2019-04-17-968660855.html"},"cveId":"CVE-2019-3398","description":"Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.","baseScore":8.8,"cpeMatches":[{"versionStartIncluding":"2.0.0","versionEndExcluding":"6.6.13"},{"versionStartIncluding":"6.7.0","versionEndExcluding":"6.12.4"},{"versionStartIncluding":"6.13.0","versionEndExcluding":"6.13.4"},{"versionStartIncluding":"6.14.0","versionEndExcluding":"6.14.3"},{"versionStartIncluding":"6.15.0","versionEndExcluding":"6.15.2"}]},{"advisory":{"name":"Confluence Security Advisory - 2021-08-25","url":"https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html"},"cveId":"CVE-2021-26084","description":"In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"6.13.23"},{"versionStartIncluding":"6.14.0","versionEndExcluding":"7.4.11"},{"versionStartIncluding":"7.5.0","versionEndExcluding":"7.11.6"},{"versionStartIncluding":"7.12.0","versionEndExcluding":"7.12.5"}]},{"advisory":{"name":"Multiple Products Security Advisory - Unrendered unicode bidirectional override characters - CVE-2021-42574","url":"https://confluence.atlassian.com/display/SECURITY/Multiple+Products+Security+Advisory+-+Unrendered+unicode+bidirectional+override+characters+-+CVE-2021-42574"},"cveId":"CVE-2021-42574","description":"An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.","baseScore":8.3,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"7.4.13"},{"versionStartIncluding":"7.5.0","versionEndExcluding":"7.12.6"},{"versionStartIncluding":"7.13.0","versionEndExcluding":"7.13.2"},{"versionStartIncluding":"7.14.0","versionEndExcluding":"7.14.1"}]},{"advisory":{"name":"CVE-2022-1471 - SnakeYAML library RCE Vulnerability impacts Multiple Products","url":"https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-impacts-multiple-products-1296171009.html"},"cveId":"CVE-2022-1471","description":"SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":"6.13.0","versionEndExcluding":"7.13.18"},{"versionStartIncluding":"7.14.0","versionEndExcluding":"7.19.10"},{"versionStartIncluding":"7.20.0","versionEndExcluding":"8.3.1"}]},{"advisory":{"name":"Confluence Security Advisory 2022-06-02","url":"https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html"},"cveId":"CVE-2022-26134","description":"In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"7.4.17"},{"versionStartIncluding":"7.5.0","versionEndExcluding":"7.13.0"},{"versionStartIncluding":"7.13.0","versionEndExcluding":"7.13.7"},{"versionStartIncluding":"7.14.0","versionEndExcluding":"7.14.3"},{"versionStartIncluding":"7.15.0","versionEndExcluding":"7.15.2"},{"versionStartIncluding":"7.16.0","versionEndExcluding":"7.16.4"},{"versionStartIncluding":"7.17.0","versionEndExcluding":"7.17.4"},{"versionStartIncluding":"7.18.0","versionEndExcluding":"7.18.1"}]},{"advisory":{"name":"Multiple Products Security Advisory - CVE-2022-26136, CVE-2022-26137","url":"https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html"},"cveId":"CVE-2022-26136","description":"A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"7.4.17"},{"versionStartIncluding":"7.5.0","versionEndExcluding":"7.13.7"},{"versionStartIncluding":"7.14.0","versionEndExcluding":"7.14.3"},{"versionStartIncluding":"7.15.0","versionEndExcluding":"7.15.2"},{"versionStartIncluding":"7.16.0","versionEndExcluding":"7.16.4"},{"versionStartIncluding":"7.17.0","versionEndExcluding":"7.17.4"},{"versionStartIncluding":"7.18.0","versionEndExcluding":"7.18.1"}]},{"advisory":{"name":"Multiple Products Security Advisory - CVE-2022-26136, CVE-2022-26137","url":"https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html"},"cveId":"CVE-2022-26137","description":"A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.","baseScore":8.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"7.4.17"},{"versionStartIncluding":"7.5.0","versionEndExcluding":"7.13.7"},{"versionStartIncluding":"7.14.0","versionEndExcluding":"7.14.3"},{"versionStartIncluding":"7.15.0","versionEndExcluding":"7.15.2"},{"versionStartIncluding":"7.16.0","versionEndExcluding":"7.16.4"},{"versionStartIncluding":"7.17.0","versionEndExcluding":"7.17.4"},{"versionStartIncluding":"7.18.0","versionEndExcluding":"7.18.1"}]},{"advisory":{"name":"Confluence Security Advisory CVE-2023-22515 - Broken Access Control Vulnerability","url":"https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515"},"cveId":"CVE-2023-22515","description":"Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. \n\nAtlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue. \\n\\nFor more details, please review the linked advisory on this CVE.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":"8.0.0","versionEndExcluding":"8.3.3"},{"versionStartIncluding":"8.4.0","versionEndExcluding":"8.4.3"},{"versionStartIncluding":"8.5.0","versionEndExcluding":"8.5.2"}]},{"advisory":{"name":"Confluence Security Advisory CVE-2023-22518 - Improper Authorization Vulnerability","url":"https://confluence.atlassian.com/pages/viewpage.action?pageId=1311473907"},"cveId":"CVE-2023-22518","description":"Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.\n\nAtlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue. \n\nFor more details, please review the linked advisory on this CVE.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"7.19.16"},{"versionStartIncluding":"7.20.0","versionEndExcluding":"8.3.4"},{"versionStartIncluding":"8.4.0","versionEndExcluding":"8.4.4"},{"versionStartIncluding":"8.5.0","versionEndExcluding":"8.5.3"},{"versionStartIncluding":"8.6.0","versionEndExcluding":"8.6.1"}]},{"advisory":{"name":"CVE-2023-22522 - RCE Vulnerability In Confluence Data Center and Confluence Server","url":"https://confluence.atlassian.com/pages/viewpage.action?pageId=1319570362"},"cveId":"CVE-2023-22522","description":"This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server versions as listed below are at risk and require immediate attention. See the advisory for additional details\n\nAtlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.","baseScore":8.8,"cpeMatches":[{"versionStartIncluding":"4.0.0","versionEndExcluding":"7.19.17"},{"versionStartIncluding":"8.0.0","versionEndExcluding":"8.4.5"},{"versionStartIncluding":"8.5.0","versionEndExcluding":"8.5.4"},{"versionStartIncluding":"8.6.0","versionEndExcluding":"8.6.2"}]},{"advisory":{"name":"CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server","url":"https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html"},"cveId":"CVE-2023-22527","description":"A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.\n\nMost recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":"8.0.0","versionEndExcluding":"8.5.4"}]},{"advisory":{"name":"CVE-2024-50379 - RCE (Remote Code Execution) org.apache.tomcat:tomcat-catalina Dependency in Confluence Data Center and Server","url":"https://confluence.atlassian.com/security/security-bulletin-february-18-2025-1510670627.html"},"cveId":"CVE-2024-50379","description":"Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration).\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.\n\nUsers are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":"7.19.6","versionEndExcluding":"8.5.19"},{"versionStartIncluding":"9.0.0","versionEndExcluding":"9.2.1"}]},{"advisory":{"name":"CVE-2024-56337 - RCE (Remote Code Execution) org.apache.tomcat:tomcat-catalina Dependency in Confluence Data Center and Server","url":"https://confluence.atlassian.com/security/security-bulletin-february-18-2025-1510670627.html"},"cveId":"CVE-2024-56337","description":"Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.\n\nThe mitigation for CVE-2024-50379 was incomplete.\n\nUsers running Tomcat on a case insensitive file system with the default servlet write enabled (readonly initialisation \nparameter set to the non-default value of false) may need additional configuration to fully mitigate CVE-2024-50379 depending on which version of Java they are using with Tomcat:\n- running on Java 8 or Java 11: the system property sun.io.useCanonCaches must be explicitly set to false (it defaults to true)\n- running on Java 17: the system property sun.io.useCanonCaches, if set, must be set to false (it defaults to false)\n- running on Java 21 onwards: no further configuration is required (the system property and the problematic cache have been removed)\n\nTomcat 11.0.3, 10.1.35 and 9.0.99 onwards will include checks that sun.io.useCanonCaches is set appropriately before allowing the default servlet to be write enabled on a case insensitive file system. Tomcat will also set sun.io.useCanonCaches to false by default where it can.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"8.5.19"},{"versionStartIncluding":"9.0.0","versionEndExcluding":"9.2.1"},{"versionStartIncluding":"9.3.0","versionEndExcluding":"9.3.1"}]}]
