CVE-2019-3398
KEV PoC largePath Traversal Leading to RCE in Atlassian Confluence Server and Data Center
CISA: Atlassian Confluence Server and Data Center Path Traversal Vulnerability
CVE-2019-3398 is a path traversal flaw (CWE-22) in the downloadallattachments resource of Atlassian Confluence Server and Data Center that allows arbitrary file writes. An attacker needs limited privileges: permission to add attachments to a page or blog, the ability to create a new space or personal space, or Admin permissions on a space; they can then write files to arbitrary filesystem locations, including paths that yield remote code execution. All Confluence Server/Data Center releases from 2.0.0 onward across the 6.6.x, 6.7.x–6.12.x, 6.13.x, 6.14.x, and 6.15.x lines are affected prior to the listed fixed versions. Because arbitrary file writes on a web application host are commonly used to plant web shells, this flaw aligns with the web-shell activity highlighted in recent NSA/ASD reporting. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and has a very high EPSS score (96.8%), with a public proof-of-concept available.
What to do: Upgrade Confluence Server/Data Center to 6.6.13, 6.12.4, 6.13.4, 6.14.3, or 6.15.2 (or later) per the vendor's instructions, prioritizing internet-facing instances given the KEV listing and near-certain exploitation. In the meantime, restrict permissions to add attachments and create spaces/personal spaces to trusted users, and hunt for signs of compromise such as unexpected files or web shells in the Confluence webroot and other arbitrary-write locations.
| Atlassian Confluence Server | All 2.0.0 and later before 6.6.13 (fixed in 6.6.13); 6.7.0 before 6.12.4 (fixed in 6.12.4); 6.13.0 before 6.13.4 (fixed in 6.13.4); 6.14.0 before 6.14.3 (fixed |
| Atlassian Confluence Data Center | All 2.0.0 and later before 6.6.13 (fixed in 6.6.13); 6.7.0 before 6.12.4 (fixed in 6.12.4); 6.13.0 before 6.13.4 (fixed in 6.13.4); 6.14.0 before 6.14.3 (fixed |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.
- Affected
- Atlassian Confluence Server and Data Center
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- atlassian
- Products
- confluence server
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H