CVE-2019-3396
Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.91% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
- Weakness
- CWE-22
- Affected
- atlassian/confluence server
- Source
- security@atlassian.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-3396
References
- http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/161065/Atlassian-Confluence-6.12.1-Template-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connectorExploit, Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/CONFSERVER-57974Issue Tracking, Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/46731/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/161065/Atlassian-Confluence-6.12.1-Template-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connectorExploit, Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/CONFSERVER-57974Issue Tracking, Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/46731/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-3396US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.