CVE-2024-21683
published 2024-05-21CVE-2024-21683: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code…
PriorityP189high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
88.27%
99.8th percentile
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.
Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html
You can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives.
This vulnerability was found internally.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | — | — |
| atlassian | confluence_data_center | >= 7.19.0 < 7.19.24 | 7.19.24 |
| atlassian | confluence_data_center | 7.20.0 – 7.20.3 | — |
| atlassian | confluence_data_center | 8.0.0 – 8.0.4 | — |
| atlassian | confluence_data_center | 8.1.0 – 8.1.4 | — |
| atlassian | confluence_data_center | 8.2.0 – 8.2.3 | — |
| atlassian | confluence_data_center | 8.3.0 – 8.3.4 | — |
| atlassian | confluence_data_center | 8.4.0 – 8.4.5 | — |
| atlassian | confluence_data_center | >= 8.5.0 < 8.5.11 | 8.5.11 |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit uploads a JavaScript file to the Confluence 'Add Language' admin endpoint (/admin/plugins/newcode/addlanguage.action). Monitor for POST requests to this path, especially with multipart/form-data content type containing .js file uploads. ↗
- →Detect the exploit chain: sequential POST to /dologin.action → /doauthenticate.action → /admin/plugins/newcode/addlanguage.action from the same source IP within a short time window. ↗
- →Alert on HTTP 302 redirect responses from both /dologin.action and /doauthenticate.action in combination with a subsequent POST to /admin/plugins/newcode/addlanguage.action — this matches the nuclei template matcher condition. ↗
- →The malicious payload is a .js file uploaded via the languageFile form field containing Rhino-engine Java ProcessBuilder calls. Inspect multipart uploads to Confluence admin endpoints for Java reflection/ProcessBuilder patterns. ↗
- →Use FOFA/Shodan fingerprint to identify exposed Confluence instances as potential targets: app="ATLASSIAN-Confluence". ↗
- →All Confluence versions prior to 7.17 are fully affected; versions up to 8.9.0 are partially affected. Prioritize detection/patching on these version ranges. ↗
- ·Exploitation requires an authenticated attacker with administrator-level privileges — this is not an unauthenticated RCE. Detection rules should account for valid admin sessions being abused. ↗
- ·The vulnerability was introduced in version 5.2 of Confluence Data Center and Server, meaning very old instances are also in scope for detection. ↗
- ·The EPSS score is extremely high (0.94054, 99.9th percentile), indicating active exploitation in the wild is highly probable — treat detections as high priority. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2024-21685: 5.16.0 to 5.16.1 Data Center Only 5.12.8 to 5.12.10 (LTS) recommended 5.4.21 to 5.4.23 (LTS)
vendor_atlassian·CVSS 5.2
CVE-2024-21685 [MEDIUM] CVE-2024-21685: 5.16.0 to 5.16.1 Data Center Only 5.12.8 to 5.12.10 (LTS) recommended 5.4.21 to 5.4.23 (LTS)
CVE-2024-21685: 5.16.0 to 5.16.1 Data Center Only 5.12.8 to 5.12.10 (LTS) recommended 5.4.21 to 5.4.23 (LTS)
5.16.0 to 5.16.1 Data Center Only 5.12.8 to 5.12.10 (LTS) recommended 5.4.21 to 5.4.23 (LTS)
CVE: CVE-2024-21685
Affected products: Jira Service Management
Atlassian
CVE-2024-22257: 8.9.0 to 8.9.2 8.8.0 to 8.8.1 8.7.1 to 8.7.2 8.6.0 to 8.6.2 8.5.0 to 8.5.10 (LTS) 8.4.0 to 8.4.5 8.3.0 to 8.3.4 8.2.0 to
vendor_atlassian·CVSS 8.9
CVE-2024-22257 [HIGH] CVE-2024-22257: 8.9.0 to 8.9.2 8.8.0 to 8.8.1 8.7.1 to 8.7.2 8.6.0 to 8.6.2 8.5.0 to 8.5.10 (LTS) 8.4.0 to 8.4.5 8.3.0 to 8.3.4 8.2.0 to
CVE-2024-22257: 8.9.0 to 8.9.2 8.8.0 to 8.8.1 8.7.1 to 8.7.2 8.6.0 to 8.6.2 8.5.0 to 8.5.10 (LTS) 8.4.0 to 8.4.5 8.3.0 to 8.3.4 8.2.0 to
8.9.0 to 8.9.2 8.8.0 to 8.8.1 8.7.1 to 8.7.2 8.6.0 to 8.6.2 8.5.0 to 8.5.10 (LTS) 8.4.0 to 8.4.5 8.3.0 to 8.3.4 8.2.0 to 8.2.3 8.1.0 to 8.1.4 8.0.0 to 8.0.4 7.20.0 to 7.20.3 7.19.0 to 7.19.23 (LTS)
CVE: CVE-2024-22257
Affected products: Confluence Data Center
Atlassian
CVE-2024-22243: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
vendor_atlassian·CVSS 8.1
CVE-2024-22243 [HIGH] CVE-2024-22243: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
CVE-2024-22243: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
CVE: CVE-2024-22243
Affected products: Confluence Data Center
Atlassian
CVE-2024-29133: DoS (Denial of Service) org.apache.commons:commons-configuration2 Dependency in Confluence Data Center and Server
vendor_atlassian·CVSS 2.0
CVE-2024-29133 [MEDIUM] CVE-2024-29133: DoS (Denial of Service) org.apache.commons:commons-configuration2 Dependency in Confluence Data Center and Server
CVE-2024-29133: DoS (Denial of Service) org.apache.commons:commons-configuration2 Dependency in Confluence Data Center and Server
DoS (Denial of Service) org.apache.commons:commons-configuration2 Dependency in Confluence Data Center and Server
CVE: CVE-2024-29133
Affected products: Confluence Data Center
Atlassian
CVE-2024-29131: DoS (Denial of Service) org.apache.commons:commons-configuration2 Dependency in Confluence Data Center and Server
vendor_atlassian·CVSS 2.0
CVE-2024-29131 [HIGH] CVE-2024-29131: DoS (Denial of Service) org.apache.commons:commons-configuration2 Dependency in Confluence Data Center and Server
CVE-2024-29131: DoS (Denial of Service) org.apache.commons:commons-configuration2 Dependency in Confluence Data Center and Server
DoS (Denial of Service) org.apache.commons:commons-configuration2 Dependency in Confluence Data Center and Server
CVE: CVE-2024-29131
Affected products: Confluence Data Center
Atlassian
CVE-2024-22259: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
vendor_atlassian·CVSS 8.1
CVE-2024-22259 [HIGH] CVE-2024-22259: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
CVE-2024-22259: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
CVE: CVE-2024-22259
Affected products: Confluence Data Center
Atlassian
CVE-2022-25647: DoS (Denial of Service) com.google.code.gson:gson Dependency in Crucible Data Center and Server
vendor_atlassian·CVSS 4.8
CVE-2022-25647 [HIGH] CVE-2022-25647: DoS (Denial of Service) com.google.code.gson:gson Dependency in Crucible Data Center and Server
CVE-2022-25647: DoS (Denial of Service) com.google.code.gson:gson Dependency in Crucible Data Center and Server
DoS (Denial of Service) com.google.code.gson:gson Dependency in Crucible Data Center and Server
CVE: CVE-2022-25647
Affected products: Crucible, Fisheye
Atlassian
CVE-2024-22262: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
vendor_atlassian·CVSS 8.1
CVE-2024-22262 [HIGH] CVE-2024-22262: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
CVE-2024-22262: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
CVE: CVE-2024-22262
Affected products: Confluence Data Center
GHSA
GHSA-vr88-2hv2-5jvf: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5
ghsa_unreviewed·2024-05-22
CVE-2024-21683 [HIGH] CWE-94 GHSA-vr88-2hv2-5jvf: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.3, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.
Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html
You can download the latest version of Confluence Data Center and Server from the download center https://www.atla
VulnCheck
Confluence Data Center and Server Remote Code Execution
vulncheck·2024·CVSS 8.8
CVE-2024-21683 [HIGH] Confluence Data Center and Server Remote Code Execution
Confluence Data Center and Server Remote Code Execution
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.3, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.vulncheck.com/v3/index/sans-dshield?cve=CVE-2024-21683; https://dashboard.shadowserver.org/statistic
Suricata
ET WEB_SPECIFIC_APPS Atlassian Confluence Data Center and Server Authenticated RCE (CVE-2024-21683)
suricata·2024-09-24·CVSS 8.8
CVE-2024-21683 [HIGH] ET WEB_SPECIFIC_APPS Atlassian Confluence Data Center and Server Authenticated RCE (CVE-2024-21683)
ET WEB_SPECIFIC_APPS Atlassian Confluence Data Center and Server Authenticated RCE (CVE-2024-21683)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Atlassian Confluence Data Center and Server Authenticated RCE (CVE-2024-21683)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/admin/plugins/newcode/addlanguage.action"; fast_pattern; http.content_type; content:"multipart/form-data|3b|"; http.request_body; content:"atl_token"; content:"newLanguageName"; content:"Content-Type|3a 20|text/javascript"; reference:url,realalphaman.substack.com/p/quick-note-about-cve-2024-21683-authenticated; reference:cve,2024-21683; classtype:web-application-activity; sid:2056094; rev:1; metadata:affected_product Atlassian_Confluence, attack_target Server, tls_sta
Metasploit
Atlassian Confluence Administrator Code Macro Remote Code Execution
metasploit·CVSS 8.8
CVE-2024-21683 [HIGH] Atlassian Confluence Administrator Code Macro Remote Code Execution
Atlassian Confluence Administrator Code Macro Remote Code Execution
This module exploits an authenticated administrator-level vulnerability in Atlassian Confluence, tracked as CVE-2024-21683. The vulnerability exists due to the Rhino script engine parser evaluating tainted data from uploaded text files. This facilitates arbitrary code execution. This exploit will authenticate, validate user privileges, extract the underlying host OS information, then trigger remote code execution. All versions of Confluence prior to 7.17 are affected, as are many versions up to 8.9.0.
Nuclei
Atlassian Confluence Data Center and Server - Remote Code Execution
nuclei·CVSS 8.8
CVE-2024-21683 [HIGH] Atlassian Confluence Data Center and Server - Remote Code Execution
Atlassian Confluence Data Center and Server - Remote Code Execution
Detects a Remote Code Execution vulnerability in Confluence Data Center and Server versions prior to X.X (affected versions). This issue allows authenticated attackers to execute arbitrary code.
Template:
id: CVE-2024-21683
info:
name: Atlassian Confluence Data Center and Server - Remote Code Execution
author: pdresearch
severity: high
description: |
Detects a Remote Code Execution vulnerability in Confluence Data Center and Server versions prior to X.X (affected versions). This issue allows authenticated attackers to execute arbitrary code.
impact: |
Authenticated attackers can execute arbitrary code on the Confluence server, potentially compromising the entire system and accessing sensitive data.
remediation: |
Updat
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Greynoiseio
NoiseLetter May 2024
blogs_greynoiseio
NoiseLetter May 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2024-05-21
Published
Exploited in the wild