Overview
- Description
- In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
- Source
- security@atlassian.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Known exploits
Data from CISA
- Vulnerability name
- Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
- Exploit added on
- Nov 3, 2021
- Exploit action due
- Nov 17, 2021
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-917
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A28735F-4827-4410-8B0B-C209ECD21DFC", "versionEndExcluding": "6.13.23" }, { "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA5224DF-97AB-4D8E-B66D-FC65A1333531", "versionEndExcluding": "7.4.11", "versionStartIncluding": "6.14.0" }, { "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E776BF66-74F1-4D8E-9099-42A4E5EEE300", "versionEndExcluding": "7.11.6", "versionStartIncluding": "7.5.0" }, { "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E11303D6-258F-4FAC-A868-BF506E7F5A4E", "versionEndExcluding": "7.12.5", "versionStartIncluding": "7.12.0" }, { "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D1FF67F-3FB4-4C0C-8263-3D4CA00A02CD", "versionEndExcluding": "6.13.23" }, { "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5CCD4D0-6BC7-442A-9D4D-43841FE40F3E", "versionEndExcluding": "7.4.11", "versionStartIncluding": "6.14.0" }, { "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF59072C-9911-4035-A75A-27D882988919", "versionEndExcluding": "7.11.6", "versionStartIncluding": "7.5.0" }, { "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BFEE2534-EBEF-438B-B616-ED4FFBC9246E", "versionEndExcluding": "7.12.5", "versionStartIncluding": "7.12.0" } ], "operator": "OR" } ] } ]