peter bassill · operator
$ cve CVE-2019-3395 JSON

CVE-2019-3395

9.8
CRITICAL · CVSS 3.0 · EPSS 6.7% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.71% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-918
On CISA KEVno
Public exploitnone known
Published2019-03-25
Last modified2026-06-17

Affected (2)

VendorProduct
atlassianconfluence
atlassianconfluence server

References

→ the Explorer  ·  watch your stack  ·  NVD