Skip to main content

Atlassian security briefs

8 published alerts for Atlassian products and services.

Actively exploited (KEV)Ransomware

CVE-2023-22527

Atlassian Confluence Data Center and Server Template Injection Vulnerability

Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22527). Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution. CISA remediation due date: 2024-02-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-22518

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22518). Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. CISA remediation due date: 2023-11-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-22515

Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian Confluence Data Center and Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-22515). Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. CISA remediation due date: 2023-10-13. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-26134

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Atlassian Confluence Server/Data Center is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-26134). Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. CISA remediation due date: 2022-06-06. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-26085

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Atlassian Confluence Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-26085). Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-26084

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

Atlassian Confluence Server and Data Center is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-26084). Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-3396

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Atlassian Confluence Server and Data Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-3396). Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-11580

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Atlassian Crowd and Crowd Data Center is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11580). Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.