CyberSec.Space Logo
返回 CVE 浏览器

CVE-2019-3396

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score64.7390%
EPSS Percentile93.38th
Published2019年3月25日
Last Modified2025年10月24日

Vulnerability Description

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

Affected Platforms (CPE)

📦
Atlassian

Confluence Server

< 6.6.12
📦
Atlassian

Confluence Server

>= 6.7.0 and < 6.12.3
📦
Atlassian

Confluence Server

>= 6.13.0 and < 6.13.3
📦
Atlassian

Confluence Server

>= 6.14.0 and < 6.14.2

References & Advisories

相关漏洞威胁