SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-26085

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

KEVMEDIUM 5.3EPSS 99.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 18 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
99.94% probability · 100th percentile
CISA KEV
Listed 28 March 2022 · due 18 April 2022 · used in ransomware campaigns
Weakness
CWE-425
Affected
atlassian/confluence data center · atlassian/confluence server
Source
security@atlassian.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-26085

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.