Atlassian Confluence Data Center vulnerabilities
59 known vulnerabilities affecting atlassian/confluence_data_center.
Total CVEs
59
CISA KEV
6
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH37MEDIUM15LOW1
Vulnerabilities
Page 2 of 3
CVE-2023-22526HIGHCVSS 8.8≥ 7.19.0, < 7.19.17≥ 8.5.0, < 8.5.5+11 more2024-01-16
CVE-2023-22526 [HIGH] CWE-94 CVE-2023-22526: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Con
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, an
nvdatlassian
CVE-2024-21672HIGHCVSS 8.8≥ 7.19.0, < 7.19.18≥ 8.5.0, < 8.5.5+10 more2024-01-16
CVE-2024-21672 [HIGH] CWE-94 CVE-2024-21672: This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Conf
This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server.
Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose assets in your environment suscept
nvdatlassian
CVE-2023-22512HIGHCVSS 7.5≥ 5.6, < 7.19.14≥ 8.0.0, < 8.5.1+1 more2024-01-16
CVE-2023-22512 [HIGH] CWE-400 CVE-2023-22512: This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluen
This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence i
nvd
CVE-2024-21674HIGHCVSS 7.5≥ 7.19.0, < 7.19.18≥ 8.5.0, < 8.5.5+10 more2024-01-16
CVE-2024-21674 [HIGH] CWE-94 CVE-2024-21674: This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Con
This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server.
Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets in your environment susceptible to
nvdatlassian
CVE-2021-31684HIGHCVSS 7.52023-12-12
CVE-2021-31684 [HIGH] CVE-2021-31684: All versions up to 7.19.16 From 8.0.x to 8.3.3 From 8.4.x to 8.4.5 From 8.5.x to 8.5.4 From 8.6.x to 8.6.2 And 8.7.0
CVE-2021-31684: All versions up to 7.19.16 From 8.0.x to 8.3.3 From 8.4.x to 8.4.5 From 8.5.x to 8.5.4 From 8.6.x to 8.6.2 And 8.7.0
All versions up to 7.19.16 From 8.0.x to 8.3.3 From 8.4.x to 8.4.5 From 8.5.x to 8.5.4 From 8.6.x to 8.6.2 And 8.7.0
CVE: CVE-2021-31684
Severity: HIGH
Affected products: Confluence Data Center
atlassian
CVE-2023-22522HIGHCVSS 8.8≥ 4.0, < 7.19.17≥ 8.0.0, < 8.4.5+7 more2023-12-06
CVE-2023-22522 [HIGH] CWE-74 CVE-2023-22522: This Template Injection vulnerability allows an authenticated attacker, including one with anonymous
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server versions as listed below are at ri
nvd
CVE-2023-42794HIGHCVSS 7.52023-11-21
CVE-2023-42794 [MEDIUM] CVE-2023-42794: DoS (Denial of Service) org.apache.tomcat:tomcat-catalina in Confluence Data Center and Server
CVE-2023-42794: DoS (Denial of Service) org.apache.tomcat:tomcat-catalina in Confluence Data Center and Server
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina in Confluence Data Center and Server
CVE: CVE-2023-42794
Severity: HIGH
Affected products: Confluence Data Center
atlassian
CVE-2022-45143HIGHCVSS 7.52023-11-21
CVE-2022-45143 [HIGH] CVE-2022-45143: org.apache.tomcat:tomcat-catalina Vulnerability in Confluence Data Center and Server
CVE-2022-45143: org.apache.tomcat:tomcat-catalina Vulnerability in Confluence Data Center and Server
org.apache.tomcat:tomcat-catalina Vulnerability in Confluence Data Center and Server
CVE: CVE-2022-45143
Severity: HIGH
Affected products: Confluence Data Center
atlassian
CVE-2023-22518CRITICALCVSS 9.8KEVPoC≥ 1.0, < 7.19.16≥ 7.20.0, < 8.3.4+4 more2023-10-31
CVE-2023-22518 [CRITICAL] CWE-863 CVE-2023-22518: All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. Th
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to
nvdatlassian
CVE-2023-22515CRITICALCVSS 9.8KEVPoC≥ 8.0.0, < 8.3.3≥ 8.4.0, < 8.4.3+19 more2023-10-04
CVE-2023-22515 [CRITICAL] CWE-20 CVE-2023-22515: Atlassian has been made aware of an issue reported by a handful of customers where external attacker
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.
Atlassian Cloud sites are not affect
nvdatlassian
CVE-2023-22505HIGHCVSS 8.8≥ 8.0.0, < 8.3.2v>= 8.0.02023-07-18
CVE-2023-22505 [HIGH] CVE-2023-22505: This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impa
nvd
CVE-2023-22508HIGHCVSS 8.8≥ 6.1.0, < 7.13.20≥ 7.14.0, < 7.19.8+2 more2023-07-18
CVE-2023-22508 [HIGH] CVE-2023-22508: This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high imp
nvd
CVE-2023-22504MEDIUMCVSS 6.5v>= 1.1.2v>= 7.14.0+1 more2023-05-25
CVE-2023-22504 [MEDIUM] CWE-434 CVE-2023-22504: Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
nvd
CVE-2023-22503MEDIUMCVSS 5.3fixed in 7.13.15≥ 7.14.0, < 7.19.7+2 more2023-05-01
CVE-2023-22503 [MEDIUM] CWE-200 CVE-2023-22503: Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.
This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.
Th
nvd
CVE-2022-42978HIGHCVSS 7.5fixed in 1.3.52022-11-15
CVE-2022-42978 [HIGH] CWE-863 CVE-2022-42978: In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled.
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.
nvd
CVE-2022-42977HIGHCVSS 7.5fixed in 1.3.52022-11-15
CVE-2022-42977 [HIGH] CWE-22 CVE-2022-42977: The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate
The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g., an SSH private key) to be downloaded.
nvd
CVE-2020-36290MEDIUMCVSS 5.4fixed in 7.4.5≥ 7.5.0, < 7.6.3+6 more2022-07-26
CVE-2020-36290 [MEDIUM] CWE-79 CVE-2020-36290: The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 b
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.
nvd
CVE-2022-26136CRITICALCVSS 9.8fixed in 7.4.17≥ 7.5.0, < 7.13.7+16 more2022-07-20
CVE-2022-26136 [CRITICAL] CWE-180 CVE-2022-26136: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass S
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released update
nvd
CVE-2022-26137HIGHCVSS 8.8fixed in 7.4.17≥ 7.5.0, < 7.13.7+16 more2022-07-20
CVE-2022-26137 [HIGH] CWE-180 CVE-2022-26137: A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause ad
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a speci
nvd
CVE-2022-26134CRITICALCVSS 9.8KEVPoC≥ 1.3, < 7.4.17≥ 7.13.0, < 7.13.7+19 more2022-06-03
CVE-2022-26134 [CRITICAL] CWE-917 CVE-2022-26134: In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists th
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2,
nvd