Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2grp-34h8-p48c

Опубликовано: 06 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

EPSS

Процентиль: 54%
0.00309
Низкий

8.8 High

CVSS3

Дефекты

CWE-74
CWE-94

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 3 лет назад

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

CVSS3: 8.8
nvd
около 3 лет назад

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

EPSS

Процентиль: 54%
0.00309
Низкий

8.8 High

CVSS3

Дефекты

CWE-74
CWE-94