peter bassill · operator
$ cve CVE-2019-3396 JSON

CVE-2019-3396 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.91% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2019-03-25
Last modified2026-06-17

CISA KEV

NameAtlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productAtlassian / Confluence Server and Data Server
Ransomware useknown

Affected (1)

VendorProduct
atlassianconfluence server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD