Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3398

Опубликовано: 18 апр. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Критический

Описание

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
Версия от 2.0 (включая) до 6.6.13 (исключая)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
Версия от 6.7.0 (включая) до 6.12.4 (исключая)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
Версия от 6.13.0 (включая) до 6.13.4 (исключая)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
Версия от 6.14.0 (включая) до 6.14.3 (исключая)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
Версия от 6.15.0 (включая) до 6.15.2 (исключая)

EPSS

Процентиль: 100%
0.93966
Критический

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 8.8
github
около 3 лет назад

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость веб-сервера Atlassian Confluence Server, существующая из-за неверного ограничения имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записать файлы в произвольные места и выполнить произвольный код

EPSS

Процентиль: 100%
0.93966
Критический

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-22
CWE-22