ZeroHour

CVE-2019-3398

KEV PoC large

Path Traversal Leading to RCE in Atlassian Confluence Server and Data Center

CISA: Atlassian Confluence Server and Data Center Path Traversal Vulnerability

CVSS 3.1
8.8 high
EPSS
97%p100
Published
()
KEV added
AI analysis

CVE-2019-3398 is a path traversal flaw (CWE-22) in the downloadallattachments resource of Atlassian Confluence Server and Data Center that allows arbitrary file writes. An attacker needs limited privileges: permission to add attachments to a page or blog, the ability to create a new space or personal space, or Admin permissions on a space; they can then write files to arbitrary filesystem locations, including paths that yield remote code execution. All Confluence Server/Data Center releases from 2.0.0 onward across the 6.6.x, 6.7.x–6.12.x, 6.13.x, 6.14.x, and 6.15.x lines are affected prior to the listed fixed versions. Because arbitrary file writes on a web application host are commonly used to plant web shells, this flaw aligns with the web-shell activity highlighted in recent NSA/ASD reporting. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and has a very high EPSS score (96.8%), with a public proof-of-concept available.

What to do: Upgrade Confluence Server/Data Center to 6.6.13, 6.12.4, 6.13.4, 6.14.3, or 6.15.2 (or later) per the vendor's instructions, prioritizing internet-facing instances given the KEV listing and near-certain exploitation. In the meantime, restrict permissions to add attachments and create spaces/personal spaces to trusted users, and hunt for signs of compromise such as unexpected files or web shells in the Confluence webroot and other arbitrary-write locations.

Affected
Atlassian Confluence ServerAll 2.0.0 and later before 6.6.13 (fixed in 6.6.13); 6.7.0 before 6.12.4 (fixed in 6.12.4); 6.13.0 before 6.13.4 (fixed in 6.13.4); 6.14.0 before 6.14.3 (fixed
Atlassian Confluence Data CenterAll 2.0.0 and later before 6.6.13 (fixed in 6.6.13); 6.7.0 before 6.12.4 (fixed in 6.12.4); 6.13.0 before 6.13.4 (fixed in 6.13.4); 6.14.0 before 6.14.3 (fixed
Estimated exposure
largetens of thousands of internet-exposed Confluence Server/Data Center instances, with a total self-hosted install base on the order of 100,000+ deployments — Public internet-wide scans (e.g., Shodan/Censys) have historically surfaced tens of thousands of exposed Confluence instances, and Confluence Server's broad enterprise self-hosted footprint suggests the full (mostly internal) deployment…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.

CISA Known Exploited Vulnerability
Affected
Atlassian Confluence Server and Data Center
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
atlassian
Products
confluence server
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news