CVE-2019-3396

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
atlassianCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
atlassianconfluence_server
𝑥
< 6.6.12
atlassianconfluence_server
6.7.0 ≤
𝑥
< 6.12.3
atlassianconfluence_server
6.13.0 ≤
𝑥
< 6.13.3
atlassianconfluence_server
6.14.0 ≤
𝑥
< 6.14.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
atlassianconfluence
𝑥
< 6.6.12
CNA
atlassianconfluence
6.7.0
CNA
atlassianconfluence
𝑥
< 6.12.3
CNA
atlassianconfluence
𝑥
< 6.13.3
CNA
atlassianconfluence
𝑥
< 6.14.2
CNA