CVE-2019-3396

CWE-22Path Traversal16 documents12 sources
9.8
CVSS
CRITICAL
EPSS94.5%(100th)
CISA KEVPublic ExploitExploited in WildRansomware Use
CISA Required Action: Apply updates per vendor instructions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDatlassian/confluence_server6.7.06.12.3+3
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

🔴Vulnerability Details

4
GHSA
OpenNMS Horizon RCE via JEXL2 expression2022-05-24
GHSA
GHSA-fr34-8fhg-2m6q: The Widget Connector macro in Atlassian Confluence Server before version 62022-05-13
CVEList
CVE-2019-3396: The Widget Connector macro in Atlassian Confluence Server before version 62019-03-25
VulnCheck
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability2019

💥Exploits & PoCs

3
Exploit-DB
Atlassian Confluence Widget Connector Macro - SSTI2021-01-22
Exploit-DB
Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit)2019-04-19
Nuclei
Atlassian Confluence Server - Path Traversal

🔍Detection Rules

1
Suricata
ET WEB_CLIENT Possible Confluence SSTI Exploitation Attempt - Leads to RCE/LFI (CVE-2019-3396)2019-05-08

📋Vendor Advisories

1
CISA
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability2021-11-03

🕵️Threat Intelligence

4
Trendmicro
CVE-2019-3396: Exploiting the Confluence Vulnerability2019-05-07
Trendmicro
CVE-2019-3396: Exploiting the Confluence Vulnerability2019-05-07
Trendmicro
AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE2019-04-26
Trendmicro
AESDDoS Botnet Exploits CVE-2019-3396 to Perform RCE2019-04-26

💬Community

2
HackerOne
LFI with potential to RCE on ██████ using CVE-2019-33962019-10-04
BugTraq
Atlassian - Confluence Security Advisory - 2019-03-202019-03-25