CVE-2019-3398
Atlassian Confluence Server and Data Center
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (th...
- CVSS
- 8.8
- EPSS
- 97.2% 99.9% percentile
- CISA KEV
- Listed
- Published
- 2019.04.19