CVE-2019-3398
Atlassian Confluence Server and Data Center Path Traversal Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 96.84% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Weakness
- CWE-22
- Affected
- atlassian/confluence server
- Source
- security@atlassian.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-3398
References
- http://packetstormsecurity.com/files/152616/Confluence-Server-Data-Center-Path-Traversal.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155235/Atlassian-Confluence-6.15.1-Directory-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155245/Atlassian-Confluence-6.15.1-Directory-Traversal.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108067Broken Link, Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/CONFSERVER-58102Issue Tracking, Patch, Vendor Advisory
- https://seclists.org/bugtraq/2019/Apr/33Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152616/Confluence-Server-Data-Center-Path-Traversal.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155235/Atlassian-Confluence-6.15.1-Directory-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155245/Atlassian-Confluence-6.15.1-Directory-Traversal.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108067Broken Link, Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/CONFSERVER-58102Issue Tracking, Patch, Vendor Advisory
- https://seclists.org/bugtraq/2019/Apr/33Mailing List, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-3398US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.