Search

Find a vulnerability

Search criteria

    38 vulnerabilities found for Confluence Data Center by Atlassian

    CVE-2026-21588 (GCVE-0-2026-21588)

    Vulnerability from cvelistv5 – Published: 2026-09-15 17:00 – Updated: 2026-09-15 23:21
    VLAI
    Summary
    This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-15 17:15 UTC
    CWE
    • DoS (Denial of Service)
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 10.2.0 to 10.2.15
    Affected: 10.1.0 to 10.1.2
    Affected: 10.0.2 to 10.0.3
    Affected: 9.5.1 to 9.5.4
    Affected: 9.4.0 to 9.4.1
    Affected: 9.3.1 to 9.3.2
    Affected: 9.2.0 to 9.2.23
    Affected: 9.1.0 to 9.1.1
    Affected: 8.9.7 to 8.9.8
    Unaffected: 10.2.17 to 10.2.18
    Unaffected: 9.2.24 to 9.2.25
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.23:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-21588",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-15T17:15:17.585833Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T23:21:14.322Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.2.0 to 10.2.15"
                },
                {
                  "status": "affected",
                  "version": "10.1.0 to 10.1.2"
                },
                {
                  "status": "affected",
                  "version": "10.0.2 to 10.0.3"
                },
                {
                  "status": "affected",
                  "version": "9.5.1 to 9.5.4"
                },
                {
                  "status": "affected",
                  "version": "9.4.0 to 9.4.1"
                },
                {
                  "status": "affected",
                  "version": "9.3.1 to 9.3.2"
                },
                {
                  "status": "affected",
                  "version": "9.2.0 to 9.2.23"
                },
                {
                  "status": "affected",
                  "version": "9.1.0 to 9.1.1"
                },
                {
                  "status": "affected",
                  "version": "8.9.7 to 8.9.8"
                },
                {
                  "status": "unaffected",
                  "version": "10.2.17 to 10.2.18"
                },
                {
                  "status": "unaffected",
                  "version": "9.2.24 to 9.2.25"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.4.1",
                      "versionStartIncluding": "9.4.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.3.2",
                      "versionStartIncluding": "9.3.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.2.23",
                      "versionStartIncluding": "9.2.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.23:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.1.1",
                      "versionStartIncluding": "9.1.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.9.8",
                      "versionStartIncluding": "8.9.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.24:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.25:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center.\r\n\r\nThis DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24\r\n\r\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Penetration Testing program."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "DoS (Denial of Service)",
                  "lang": "en",
                  "type": "DoS (Denial of Service)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-15T17:00:00.390Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1822852209"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-104451"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2026-21588",
        "datePublished": "2026-09-15T17:00:00.390Z",
        "dateReserved": "2026-01-01T00:00:40.722Z",
        "dateUpdated": "2026-09-15T23:21:14.322Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-21586 (GCVE-0-2026-21586)

    Vulnerability from cvelistv5 – Published: 2026-09-15 17:00 – Updated: 2026-09-17 11:58
    VLAI
    Summary
    This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 03:56 UTC
    CWE
    • Improper Authorization
    • CWE-285 - Improper Authorization
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 10.2.1 to 10.2.15
    Affected: 10.1.0 to 10.1.2
    Affected: 10.0.2 to 10.0.3
    Affected: 9.5.1 to 9.5.4
    Affected: 9.4.0 to 9.4.1
    Affected: 9.3.1 to 9.3.2
    Affected: 9.2.0 to 9.2.23
    Affected: 9.1.1
    Affected: 8.9.7 to 8.9.8
    Affected: 8.5.16 to 8.5.31
    Affected: 7.19.28 to 7.19.30
    Unaffected: 10.2.17 to 10.2.18
    Unaffected: 9.2.24 to 9.2.25
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.23:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.1.1:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.25:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.26:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.27:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.28:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.29:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.30:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.31:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-21586",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T03:56:45.509123Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-285",
                    "description": "CWE-285 Improper Authorization",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T11:58:46.365Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.2.1 to 10.2.15"
                },
                {
                  "status": "affected",
                  "version": "10.1.0 to 10.1.2"
                },
                {
                  "status": "affected",
                  "version": "10.0.2 to 10.0.3"
                },
                {
                  "status": "affected",
                  "version": "9.5.1 to 9.5.4"
                },
                {
                  "status": "affected",
                  "version": "9.4.0 to 9.4.1"
                },
                {
                  "status": "affected",
                  "version": "9.3.1 to 9.3.2"
                },
                {
                  "status": "affected",
                  "version": "9.2.0 to 9.2.23"
                },
                {
                  "status": "affected",
                  "version": "9.1.1"
                },
                {
                  "status": "affected",
                  "version": "8.9.7 to 8.9.8"
                },
                {
                  "status": "affected",
                  "version": "8.5.16 to 8.5.31"
                },
                {
                  "status": "affected",
                  "version": "7.19.28 to 7.19.30"
                },
                {
                  "status": "unaffected",
                  "version": "10.2.17 to 10.2.18"
                },
                {
                  "status": "unaffected",
                  "version": "9.2.24 to 9.2.25"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.4.1",
                      "versionStartIncluding": "9.4.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.3.2",
                      "versionStartIncluding": "9.3.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.2.23",
                      "versionStartIncluding": "9.2.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.23:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.1.1:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.9.8",
                      "versionStartIncluding": "8.9.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.5.31",
                      "versionStartIncluding": "8.5.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.25:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.26:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.27:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.28:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.29:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.30:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.31:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "7.19.30",
                      "versionStartIncluding": "7.19.28",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.24:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.25:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center.\r\n\r\nThis Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24\r\n\r\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Penetration Testing program."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Authorization",
                  "lang": "en",
                  "type": "Improper Authorization"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-15T17:00:00.365Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1822852209"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-104418"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2026-21586",
        "datePublished": "2026-09-15T17:00:00.365Z",
        "dateReserved": "2026-01-01T00:00:40.722Z",
        "dateUpdated": "2026-09-17T11:58:46.365Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-21580 (GCVE-0-2026-21580)

    Vulnerability from cvelistv5 – Published: 2026-08-18 22:00 – Updated: 2026-08-21 14:45
    VLAI
    Summary
    This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center and Server from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Bug Bounty program.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-21 03:55 UTC
    CWE
    • Stored XSS
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 10.2.0 to 10.2.11
    Affected: 10.1.0 to 10.1.2
    Affected: 10.0.2 to 10.0.3
    Affected: 9.5.1 to 9.5.4
    Affected: 9.4.0 to 9.4.1
    Affected: 9.3.1 to 9.3.2
    Affected: 9.2.0 to 9.2.20
    Affected: 9.1.0 to 9.1.1
    Affected: 9.0.3
    Affected: 8.9.6 to 8.9.8
    Affected: 8.5.15 to 8.5.31
    Affected: 7.19.27 to 7.19.30
    Unaffected: 10.2.13 to 10.2.15
    Unaffected: 9.2.21 to 9.2.23
    Create a notification for this product.
    Atlassian Confluence Server Affected: 8.5.15 to 8.5.31
    Affected: 7.19.27 to 7.19.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-21580",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-21T03:55:22.938181Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-79",
                    "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-21T14:45:07.562Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.2.0 to 10.2.11"
                },
                {
                  "status": "affected",
                  "version": "10.1.0 to 10.1.2"
                },
                {
                  "status": "affected",
                  "version": "10.0.2 to 10.0.3"
                },
                {
                  "status": "affected",
                  "version": "9.5.1 to 9.5.4"
                },
                {
                  "status": "affected",
                  "version": "9.4.0 to 9.4.1"
                },
                {
                  "status": "affected",
                  "version": "9.3.1 to 9.3.2"
                },
                {
                  "status": "affected",
                  "version": "9.2.0 to 9.2.20"
                },
                {
                  "status": "affected",
                  "version": "9.1.0 to 9.1.1"
                },
                {
                  "status": "affected",
                  "version": "9.0.3"
                },
                {
                  "status": "affected",
                  "version": "8.9.6 to 8.9.8"
                },
                {
                  "status": "affected",
                  "version": "8.5.15 to 8.5.31"
                },
                {
                  "status": "affected",
                  "version": "7.19.27 to 7.19.30"
                },
                {
                  "status": "unaffected",
                  "version": "10.2.13 to 10.2.15"
                },
                {
                  "status": "unaffected",
                  "version": "9.2.21 to 9.2.23"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "8.5.15 to 8.5.31"
                },
                {
                  "status": "affected",
                  "version": "7.19.27 to 7.19.30"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.4.1",
                      "versionStartIncluding": "9.4.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.3.2",
                      "versionStartIncluding": "9.3.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.2.20",
                      "versionStartIncluding": "9.2.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.1.1",
                      "versionStartIncluding": "9.1.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.0.3:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.9.8",
                      "versionStartIncluding": "8.9.6",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.5.31",
                      "versionStartIncluding": "8.5.15",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.25:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.26:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.27:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.28:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.29:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.30:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.31:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "7.19.30",
                      "versionStartIncluding": "7.19.27",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.23:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.5.31",
                      "versionStartIncluding": "8.5.15",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.22:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.23:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.24:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.25:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.26:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.27:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.28:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.29:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.30:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:8.5.31:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "7.19.30",
                      "versionStartIncluding": "7.19.27",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server.\r\n\r\nThis Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked.\r\n\r\nAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21\r\n\r\n Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center and Server from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Bug Bounty program."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Stored XSS",
                  "lang": "en",
                  "type": "Stored XSS"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T22:00:00.396Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999768"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-104381"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2026-21580",
        "datePublished": "2026-08-18T22:00:00.396Z",
        "dateReserved": "2026-01-01T00:00:40.721Z",
        "dateUpdated": "2026-08-21T14:45:07.562Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-21577 (GCVE-0-2026-21577)

    Vulnerability from cvelistv5 – Published: 2026-07-21 17:00 – Updated: 2026-07-22 18:48
    VLAI
    Summary
    This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-22 18:32 UTC
    CWE
    • DoS (Denial of Service)
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 10.2.0 to 10.2.6
    Affected: 10.1.0 to 10.1.2
    Affected: 10.0.2 to 10.0.3
    Affected: 9.5.1 to 9.5.4
    Affected: 9.4.0 to 9.4.1
    Affected: 9.3.1 to 9.3.2
    Affected: 9.2.0 to 9.2.15
    Affected: 9.1.0 to 9.1.1
    Affected: 9.0.1 to 9.0.3
    Unaffected: 10.2.7 to 10.2.14
    Unaffected: 9.2.17 to 9.2.22
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-21577",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-22T18:32:38.139315Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-22T18:48:52.568Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.2.0 to 10.2.6"
                },
                {
                  "status": "affected",
                  "version": "10.1.0 to 10.1.2"
                },
                {
                  "status": "affected",
                  "version": "10.0.2 to 10.0.3"
                },
                {
                  "status": "affected",
                  "version": "9.5.1 to 9.5.4"
                },
                {
                  "status": "affected",
                  "version": "9.4.0 to 9.4.1"
                },
                {
                  "status": "affected",
                  "version": "9.3.1 to 9.3.2"
                },
                {
                  "status": "affected",
                  "version": "9.2.0 to 9.2.15"
                },
                {
                  "status": "affected",
                  "version": "9.1.0 to 9.1.1"
                },
                {
                  "status": "affected",
                  "version": "9.0.1 to 9.0.3"
                },
                {
                  "status": "unaffected",
                  "version": "10.2.7 to 10.2.14"
                },
                {
                  "status": "unaffected",
                  "version": "9.2.17 to 9.2.22"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.4.1",
                      "versionStartIncluding": "9.4.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.3.2",
                      "versionStartIncluding": "9.3.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.2.15",
                      "versionStartIncluding": "9.2.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.1.1",
                      "versionStartIncluding": "9.1.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.0.3",
                      "versionStartIncluding": "9.0.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center.\r\n\r\nThis DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17\r\n\r\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Penetration Testing program."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "DoS (Denial of Service)",
                  "lang": "en",
                  "type": "DoS (Denial of Service)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-21T17:00:00.483Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-104334"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2026-21577",
        "datePublished": "2026-07-21T17:00:00.483Z",
        "dateReserved": "2026-01-01T00:00:40.721Z",
        "dateUpdated": "2026-07-22T18:48:52.568Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-21579 (GCVE-0-2026-21579)

    Vulnerability from cvelistv5 – Published: 2026-07-21 17:00 – Updated: 2026-07-22 18:48
    VLAI
    Summary
    This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.22 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.14 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Atlassian (Internal) program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-22 18:33 UTC
    CWE
    • Information Disclosure
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 10.2.0 to 10.2.13
    Affected: 10.1.0 to 10.1.2
    Affected: 10.0.2 to 10.0.3
    Affected: 9.2.0 to 9.2.21
    Affected: 9.1.0 to 9.1.1
    Affected: 9.0.1 to 9.0.3
    Affected: 8.9.5 to 8.9.8
    Affected: 8.5.14 to 8.5.31
    Affected: 7.19.26 to 7.19.30
    Unaffected: 10.2.14
    Unaffected: 9.2.22
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.25:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.26:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.27:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.28:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.29:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.30:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.31:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-21579",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-22T18:33:05.618013Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-200",
                    "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-22T18:48:58.801Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "10.2.0 to 10.2.13"
                },
                {
                  "status": "affected",
                  "version": "10.1.0 to 10.1.2"
                },
                {
                  "status": "affected",
                  "version": "10.0.2 to 10.0.3"
                },
                {
                  "status": "affected",
                  "version": "9.2.0 to 9.2.21"
                },
                {
                  "status": "affected",
                  "version": "9.1.0 to 9.1.1"
                },
                {
                  "status": "affected",
                  "version": "9.0.1 to 9.0.3"
                },
                {
                  "status": "affected",
                  "version": "8.9.5 to 8.9.8"
                },
                {
                  "status": "affected",
                  "version": "8.5.14 to 8.5.31"
                },
                {
                  "status": "affected",
                  "version": "7.19.26 to 7.19.30"
                },
                {
                  "status": "unaffected",
                  "version": "10.2.14"
                },
                {
                  "status": "unaffected",
                  "version": "9.2.22"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.2.21",
                      "versionStartIncluding": "9.2.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.10:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.11:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.12:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.14:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.15:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.16:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.17:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.18:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.19:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.20:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.21:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.1.1",
                      "versionStartIncluding": "9.1.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.0.3",
                      "versionStartIncluding": "9.0.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.9.8",
                      "versionStartIncluding": "8.9.5",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.5.31",
                      "versionStartIncluding": "8.5.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.25:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.26:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.27:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.28:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.29:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.30:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.31:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "7.19.30",
                      "versionStartIncluding": "7.19.26",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.22:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center.\r\n\r\nThis Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.22\r\n\r\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.14\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Atlassian (Internal) program."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "Information Disclosure"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-21T17:00:00.404Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1821999345"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-104340"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2026-21579",
        "datePublished": "2026-07-21T17:00:00.404Z",
        "dateReserved": "2026-01-01T00:00:40.721Z",
        "dateUpdated": "2026-07-22T18:48:58.801Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-22166 (GCVE-0-2025-22166)

    Vulnerability from cvelistv5 – Published: 2025-10-21 16:00 – Updated: 2025-10-21 16:21
    VLAI
    Summary
    This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.25 Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.7 Confluence Data Center and Server 10.0: Upgrade to a release greater than or equal to 10.0.2 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Atlassian (Internal) program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-10-21 16:21 UTC
    CWE
    • DoS (Denial of Service)
    • CWE-405 - Asymmetric Resource Consumption (Amplification)
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 9.5.1 to 9.5.4
    Affected: 9.4.0 to 9.4.1
    Affected: 9.3.1 to 9.3.2
    Affected: 9.2.0 to 9.2.6
    Affected: 9.1.0 to 9.1.1
    Affected: 9.0.1 to 9.0.3
    Affected: 8.9.0 to 8.9.8
    Affected: 8.8.0 to 8.8.1
    Affected: 8.7.1 to 8.7.2
    Affected: 8.6.1 to 8.6.2
    Affected: 8.5.3 to 8.5.24
    Affected: 7.19.16 to 7.19.30
    Unaffected: 10.0.2 to 10.0.3
    Unaffected: 9.2.7 to 9.2.9
    Unaffected: 8.5.25 to 8.5.27
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.13:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-22166",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-10-21T16:21:21.142041Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-405",
                    "description": "CWE-405 Asymmetric Resource Consumption (Amplification)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T16:21:27.828Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "9.5.1 to 9.5.4"
                },
                {
                  "status": "affected",
                  "version": "9.4.0 to 9.4.1"
                },
                {
                  "status": "affected",
                  "version": "9.3.1 to 9.3.2"
                },
                {
                  "status": "affected",
                  "version": "9.2.0 to 9.2.6"
                },
                {
                  "status": "affected",
                  "version": "9.1.0 to 9.1.1"
                },
                {
                  "status": "affected",
                  "version": "9.0.1 to 9.0.3"
                },
                {
                  "status": "affected",
                  "version": "8.9.0 to 8.9.8"
                },
                {
                  "status": "affected",
                  "version": "8.8.0 to 8.8.1"
                },
                {
                  "status": "affected",
                  "version": "8.7.1 to 8.7.2"
                },
                {
                  "status": "affected",
                  "version": "8.6.1 to 8.6.2"
                },
                {
                  "status": "affected",
                  "version": "8.5.3 to 8.5.24"
                },
                {
                  "status": "affected",
                  "version": "7.19.16 to 7.19.30"
                },
                {
                  "status": "unaffected",
                  "version": "10.0.2 to 10.0.3"
                },
                {
                  "status": "unaffected",
                  "version": "9.2.7 to 9.2.9"
                },
                {
                  "status": "unaffected",
                  "version": "8.5.25 to 8.5.27"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.4.1",
                      "versionStartIncluding": "9.4.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.4.1:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.3.2",
                      "versionStartIncluding": "9.3.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.2.6",
                      "versionStartIncluding": "9.2.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.2:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.3:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.4:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.5:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.6:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.1.1",
                      "versionStartIncluding": "9.1.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "9.0.3",
                      "versionStartIncluding": "9.0.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.9.8",
                      "versionStartIncluding": "8.9.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.8.1",
                      "versionStartIncluding": "8.8.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.7.2",
                      "versionStartIncluding": "8.7.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.6.2",
                      "versionStartIncluding": "8.6.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "8.5.24",
                      "versionStartIncluding": "8.5.3",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.13:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.22:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.23:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.24:*:*:*:*:*:*:*",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "7.19.30",
                      "versionStartIncluding": "7.19.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.7:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.8:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:9.2.9:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.25:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.26:*:*:*:*:*:*:*",
                      "vulnerable": false
                    },
                    {
                      "criteria": "cpe:2.3:a:atlassian:confluence_data_center:8.5.27:*:*:*:*:*:*:*",
                      "vulnerable": false
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center.\r\n\r\nThis DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.25\r\n Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.7\r\n Confluence Data Center and Server 10.0: Upgrade to a release greater than or equal to 10.0.2\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Atlassian (Internal) program."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "DoS (Denial of Service)",
                  "lang": "en",
                  "type": "DoS (Denial of Service)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-21T16:00:05.978Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1652920034"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-100907"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2025-22166",
        "datePublished": "2025-10-21T16:00:05.978Z",
        "dateReserved": "2025-01-01T00:01:27.176Z",
        "dateUpdated": "2025-10-21T16:21:27.828Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22512 (GCVE-0-2023-22512)

    Vulnerability from cvelistv5 – Published: 2025-03-17 22:34 – Updated: 2025-05-12 15:39
    VLAI
    Summary
    This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.14 Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.1 Confluence Data Center and Server 8.6 or above: No need to upgrade, you're already on a patched version See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ]). This vulnerability was reported via our Bug Bounty program.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-12 15:38 UTC
    CWE
    • DoS (Denial of Service)
    • CWE-400 - Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 5.6.0
    Affected: >= 5.6.0
    Unaffected: >= 7.19.13
    Unaffected: >= 7.19.14
    Unaffected: >= 8.5.1
    Unaffected: >= 8.6.0
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 5.6.0
    Affected: >= 5.6.0
    Unaffected: >= 7.19.13
    Unaffected: >= 7.19.14
    Unaffected: >= 8.5.1
    Unaffected: >= 8.6.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22512",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-12T15:38:47.977501Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-12T15:39:27.035Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 5.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.6.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.13"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.14"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.6.0"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 5.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 5.6.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.13"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.14"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.6.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.14 Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.1 Confluence Data Center and Server 8.6 or above: No need to upgrade, you\u0027re already on a patched version See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ]). This vulnerability was reported via our Bug Bounty program."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "DoS (Denial of Service)",
                  "lang": "en",
                  "type": "DoS (Denial of Service)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-17T22:34:42.950Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1283691616"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-91258"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22512",
        "datePublished": "2025-03-17T22:34:42.950Z",
        "dateReserved": "2023-01-01T00:01:22.330Z",
        "dateUpdated": "2025-05-12T15:39:27.035Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21703 (GCVE-0-2024-21703)

    Vulnerability from cvelistv5 – Published: 2024-11-27 17:00 – Updated: 2024-11-27 17:33
    VLAI
    Summary
    This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about the Confluence Data Center configuration which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to the latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.18 * Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.5 * Confluence Data Center and Server 8.7: Upgrade to a release greater than or equal to 8.7.2 * Confluence Data Center and Server 8.8: Upgrade to a release greater than or equal to 8.8.0 See the release notes (https://confluence.atlassian.com/conf88/confluence-release-notes-1354501008.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ). This vulnerability was reported via our Atlassian Bug Bounty Program by Chris Elliot.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-27 17:24 UTC
    CWE
    • Security Misconfiguration
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 8.7.1
    Unaffected: 8.8.0 to 8.8.1
    Unaffected: 8.7.2
    Unaffected: 8.5.5 to 8.5.17
    Unaffected: 7.19.18 to 7.19.29
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: 8.5.5 to 8.5.17
    Unaffected: 7.19.18 to 7.19.29
    Create a notification for this product.
    atlassian confluence_data_center Affected: 7.19 , < 7.1918 (custom)
    Affected: 8.5 , < 8.5.5 (custom)
    Affected: 8.7 , < 8.7.2 (custom)
    Affected: 8.8 , < 8.8.0 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 7.19 , < 7.19.18 (custom)
    Affected: 8.5 , < 8.5.5 (custom)
    Affected: 8.7 , < 8.7.2 (custom)
    Affected: 8.8 , < 8.8.0 (custom)
        cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.1918",
                    "status": "affected",
                    "version": "7.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.5.5",
                    "status": "affected",
                    "version": "8.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.7.2",
                    "status": "affected",
                    "version": "8.7",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.8.0",
                    "status": "affected",
                    "version": "8.8",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.19.18",
                    "status": "affected",
                    "version": "7.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.5.5",
                    "status": "affected",
                    "version": "8.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.7.2",
                    "status": "affected",
                    "version": "8.7",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.8.0",
                    "status": "affected",
                    "version": "8.8",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.4,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21703",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-27T17:24:22.500451Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-732",
                    "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-27T17:33:53.585Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "8.7.1"
                },
                {
                  "status": "unaffected",
                  "version": "8.8.0 to 8.8.1"
                },
                {
                  "status": "unaffected",
                  "version": "8.7.2"
                },
                {
                  "status": "unaffected",
                  "version": "8.5.5 to 8.5.17"
                },
                {
                  "status": "unaffected",
                  "version": "7.19.18 to 7.19.29"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "8.5.5 to 8.5.17"
                },
                {
                  "status": "unaffected",
                  "version": "7.19.18 to 7.19.29"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Chris Elliot"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations.\n\n\n\nThis Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about the Confluence Data Center configuration which has high impact to confidentiality, high impact to integrity,  high impact to availability, and no user interaction.\n\n\n\nAtlassian recommends that Confluence Data Center and Server customers upgrade to the latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\n* Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.18 \n* Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.5\n* Confluence Data Center and Server 8.7: Upgrade to a release greater than or equal to 8.7.2\n* Confluence Data Center and Server 8.8: Upgrade to a release greater than or equal to 8.8.0\n\n\n\nSee the release notes (https://confluence.atlassian.com/conf88/confluence-release-notes-1354501008.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ). \n\nThis vulnerability was reported via our Atlassian Bug Bounty Program by Chris Elliot."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Security Misconfiguration",
                  "lang": "en",
                  "type": "Security Misconfiguration"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-27T17:00:01.507Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-98413"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2024-21703",
        "datePublished": "2024-11-27T17:00:01.507Z",
        "dateReserved": "2024-01-01T00:05:33.849Z",
        "dateUpdated": "2024-11-27T17:33:53.585Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21690 (GCVE-0-2024-21690)

    Vulnerability from cvelistv5 – Published: 2024-08-21 16:05 – Updated: 2024-11-06 18:47
    VLAI
    Summary
    This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. This Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability, with a CVSS Score of 7.1, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser and force a end user to execute unwanted actions on a web application in which they're currently authenticated which has high impact to confidentiality, low impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.26 * Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.14 * Confluence Data Center and Server 9.0: Upgrade to a release greater than or equal to 9.0.1 See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives). This vulnerability was reported via our Bug Bounty program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-22 13:51 UTC
    CWE
    • Reflected XSS
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 8.9.0 to 8.9.5
    Affected: 8.8.0 to 8.8.1
    Affected: 8.7.1 to 8.7.2
    Affected: 8.6.0 to 8.6.2
    Affected: 8.5.0 to 8.5.12
    Affected: 8.4.0 to 8.4.5
    Affected: 8.3.0 to 8.3.4
    Affected: 8.2.0 to 8.2.3
    Affected: 8.1.0 to 8.1.4
    Affected: 8.0.0 to 8.0.4
    Affected: 7.20.0 to 7.20.3
    Unaffected: 9.0.1 to 9.0.2
    Unaffected: 8.5.14
    Unaffected: 7.19.26
    Create a notification for this product.
    Atlassian Confluence Server Affected: 8.5.0 to 8.5.12
    Affected: 8.4.0 to 8.4.5
    Affected: 8.3.0 to 8.3.4
    Affected: 8.2.0 to 8.2.3
    Affected: 8.1.0 to 8.1.4
    Affected: 8.0.0 to 8.0.4
    Affected: 7.20.0 to 7.20.3
    Unaffected: 8.5.14
    Unaffected: 7.19.26
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21690",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-22T13:51:34.740469Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-79",
                    "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-06T18:47:21.992Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "8.9.0 to 8.9.5"
                },
                {
                  "status": "affected",
                  "version": "8.8.0 to 8.8.1"
                },
                {
                  "status": "affected",
                  "version": "8.7.1 to 8.7.2"
                },
                {
                  "status": "affected",
                  "version": "8.6.0 to 8.6.2"
                },
                {
                  "status": "affected",
                  "version": "8.5.0 to 8.5.12"
                },
                {
                  "status": "affected",
                  "version": "8.4.0 to 8.4.5"
                },
                {
                  "status": "affected",
                  "version": "8.3.0 to 8.3.4"
                },
                {
                  "status": "affected",
                  "version": "8.2.0 to 8.2.3"
                },
                {
                  "status": "affected",
                  "version": "8.1.0 to 8.1.4"
                },
                {
                  "status": "affected",
                  "version": "8.0.0 to 8.0.4"
                },
                {
                  "status": "affected",
                  "version": "7.20.0 to 7.20.3"
                },
                {
                  "status": "unaffected",
                  "version": "9.0.1 to 9.0.2"
                },
                {
                  "status": "unaffected",
                  "version": "8.5.14"
                },
                {
                  "status": "unaffected",
                  "version": "7.19.26"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "8.5.0 to 8.5.12"
                },
                {
                  "status": "affected",
                  "version": "8.4.0 to 8.4.5"
                },
                {
                  "status": "affected",
                  "version": "8.3.0 to 8.3.4"
                },
                {
                  "status": "affected",
                  "version": "8.2.0 to 8.2.3"
                },
                {
                  "status": "affected",
                  "version": "8.1.0 to 8.1.4"
                },
                {
                  "status": "affected",
                  "version": "8.0.0 to 8.0.4"
                },
                {
                  "status": "affected",
                  "version": "7.20.0 to 7.20.3"
                },
                {
                  "status": "unaffected",
                  "version": "8.5.14"
                },
                {
                  "status": "unaffected",
                  "version": "7.19.26"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. \n\t\n\tThis Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability, with a CVSS Score of 7.1, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser and force a end user to execute unwanted actions on a web application in which they\u0027re currently authenticated which has high impact to confidentiality, low impact to integrity, no impact to availability, and requires user interaction. \n\t\n\tAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\t\t\n\t\t* Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.26\n\t\t\n\t\t* Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.14\n\t\t\n\t\t* Confluence Data Center and Server 9.0: Upgrade to a release greater than or equal to 9.0.1\n\t\t\n\t\t\n\t\n\tSee the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives). \n\t\n\tThis vulnerability was reported via our Bug Bounty program."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Reflected XSS",
                  "lang": "en",
                  "type": "Reflected XSS"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-21T17:00:02.995Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1431535667"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-97720"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2024-21690",
        "datePublished": "2024-08-21T16:05:00.394Z",
        "dateReserved": "2024-01-01T00:05:33.847Z",
        "dateUpdated": "2024-11-06T18:47:21.992Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21686 (GCVE-0-2024-21686)

    Vulnerability from cvelistv5 – Published: 2024-07-16 20:00 – Updated: 2025-03-19 18:24
    VLAI
    Summary
    This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives). This vulnerability was reported via our Bug Bounty program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-05 15:34 UTC
    CWE
    • Stored XSS
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 8.9.0
    Affected: 8.8.0 to 8.8.1
    Affected: 8.7.1 to 8.7.2
    Affected: 8.6.0 to 8.6.2
    Affected: 8.5.0 to 8.5.8
    Affected: 8.4.0 to 8.4.5
    Affected: 8.3.0 to 8.3.4
    Affected: 8.2.0 to 8.2.3
    Affected: 8.1.0 to 8.1.4
    Affected: 8.0.0 to 8.0.4
    Affected: 7.20.0 to 7.20.3
    Affected: 7.19.0 to 7.19.21
    Unaffected: 8.9.1 to 8.9.4
    Unaffected: 8.5.9 to 8.5.12
    Unaffected: 7.19.22 to 7.19.25
    Create a notification for this product.
    Atlassian Confluence Server Affected: 8.5.0 to 8.5.8
    Affected: 8.4.0 to 8.4.5
    Affected: 8.3.0 to 8.3.4
    Affected: 8.2.0 to 8.2.3
    Affected: 8.1.0 to 8.1.4
    Affected: 8.0.0 to 8.0.4
    Affected: 7.20.0 to 7.20.3
    Affected: 7.19.0 to 7.19.21
    Unaffected: 8.5.9 to 8.5.12
    Unaffected: 7.19.22 to 7.19.25
    Create a notification for this product.
    atlassian confluence_data_center Affected: 8.9.0
    Affected: 8.8.0 , ≤ 8.8.1 (custom)
    Affected: 8.7.1 , ≤ 8.7.2 (custom)
    Affected: 8.6.0 , ≤ 8.6.2 (custom)
    Affected: 8.5.0 , ≤ 8.5.8 (custom)
    Affected: 8.4.0 , ≤ 8.4.5 (custom)
    Affected: 8.3.0 , ≤ 8.3.4 (custom)
    Affected: 8.2.0 , ≤ 8.2.3 (custom)
    Affected: 8.1.0 , ≤ 8.1.4 (custom)
    Affected: 8.0.0 , ≤ 8.0.4 (custom)
    Affected: 7.20.0 , ≤ 7.20.3 (custom)
    Affected: 7.19.0 , ≤ 7.19.21 (custom)
    Affected: 8.9.1 , ≤ 8.9.4 (custom)
    Affected: 8.5.9 , ≤ 8.5.12 (custom)
    Affected: 7.19.22 , ≤ 7.19.25 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:-:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 8.5.0 , ≤ 8.5.8 (custom)
    Affected: 8.4.0 , ≤ 8.4.5 (custom)
    Affected: 8.3.0 , ≤ 8.3.4 (custom)
    Affected: 8.2.0 , ≤ 8.2.3 (custom)
    Affected: 8.1.0 , ≤ 8.1.4 (custom)
    Affected: 8.0.0 , ≤ 8.0.4 (custom)
    Affected: 7.20.0 , ≤ 7.20.3 (custom)
    Affected: 7.19.0 , ≤ 7.19.21 (custom)
    Affected: 8.5.9 , ≤ 8.5.12 (custom)
    Affected: 7.19.22 , ≤ 7.19.25 (custom)
        cpe:2.3:a:atlassian:confluence_server:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T22:27:36.033Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1417150917"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-96134"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.9.0"
                  },
                  {
                    "lessThanOrEqual": "8.8.1",
                    "status": "affected",
                    "version": "8.8.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.7.2",
                    "status": "affected",
                    "version": "8.7.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.6.2",
                    "status": "affected",
                    "version": "8.6.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.5.8",
                    "status": "affected",
                    "version": "8.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.4.5",
                    "status": "affected",
                    "version": "8.4.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.3.4",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.2.3",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.1.4",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.0.4",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.20.3",
                    "status": "affected",
                    "version": "7.20.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.19.21",
                    "status": "affected",
                    "version": "7.19.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.9.4",
                    "status": "affected",
                    "version": "8.9.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.5.12",
                    "status": "affected",
                    "version": "8.5.9",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.19.25",
                    "status": "affected",
                    "version": "7.19.22",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThanOrEqual": "8.5.8",
                    "status": "affected",
                    "version": "8.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.4.5",
                    "status": "affected",
                    "version": "8.4.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.3.4",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.2.3",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.1.4",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.0.4",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.20.3",
                    "status": "affected",
                    "version": "7.20.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.19.21",
                    "status": "affected",
                    "version": "7.19.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.5.12",
                    "status": "affected",
                    "version": "8.5.9",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.19.25",
                    "status": "affected",
                    "version": "7.19.22",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21686",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-05T15:34:59.884690Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-79",
                    "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-19T18:24:42.880Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "8.9.0"
                },
                {
                  "status": "affected",
                  "version": "8.8.0 to 8.8.1"
                },
                {
                  "status": "affected",
                  "version": "8.7.1 to 8.7.2"
                },
                {
                  "status": "affected",
                  "version": "8.6.0 to 8.6.2"
                },
                {
                  "status": "affected",
                  "version": "8.5.0 to 8.5.8"
                },
                {
                  "status": "affected",
                  "version": "8.4.0 to 8.4.5"
                },
                {
                  "status": "affected",
                  "version": "8.3.0 to 8.3.4"
                },
                {
                  "status": "affected",
                  "version": "8.2.0 to 8.2.3"
                },
                {
                  "status": "affected",
                  "version": "8.1.0 to 8.1.4"
                },
                {
                  "status": "affected",
                  "version": "8.0.0 to 8.0.4"
                },
                {
                  "status": "affected",
                  "version": "7.20.0 to 7.20.3"
                },
                {
                  "status": "affected",
                  "version": "7.19.0 to 7.19.21"
                },
                {
                  "status": "unaffected",
                  "version": "8.9.1 to 8.9.4"
                },
                {
                  "status": "unaffected",
                  "version": "8.5.9 to 8.5.12"
                },
                {
                  "status": "unaffected",
                  "version": "7.19.22 to 7.19.25"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "8.5.0 to 8.5.8"
                },
                {
                  "status": "affected",
                  "version": "8.4.0 to 8.4.5"
                },
                {
                  "status": "affected",
                  "version": "8.3.0 to 8.3.4"
                },
                {
                  "status": "affected",
                  "version": "8.2.0 to 8.2.3"
                },
                {
                  "status": "affected",
                  "version": "8.1.0 to 8.1.4"
                },
                {
                  "status": "affected",
                  "version": "8.0.0 to 8.0.4"
                },
                {
                  "status": "affected",
                  "version": "7.20.0 to 7.20.3"
                },
                {
                  "status": "affected",
                  "version": "7.19.0 to 7.19.21"
                },
                {
                  "status": "unaffected",
                  "version": "8.5.9 to 8.5.12"
                },
                {
                  "status": "unaffected",
                  "version": "7.19.22 to 7.19.25"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server.\n\nThis Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires user interaction.\n\nAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE\n\nSee the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives).\n\nThis vulnerability was reported via our Bug Bounty program."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Stored XSS",
                  "lang": "en",
                  "type": "Stored XSS"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-16T20:00:02.617Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1417150917"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-96134"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2024-21686",
        "datePublished": "2024-07-16T20:00:02.156Z",
        "dateReserved": "2024-01-01T00:05:33.847Z",
        "dateUpdated": "2025-03-19T18:24:42.880Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21683 (GCVE-0-2024-21683)

    Vulnerability from cvelistv5 – Published: 2024-05-21 23:00 – Updated: 2025-05-12 15:22
    VLAI
    Summary
    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html You can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives. This vulnerability was found internally.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-20 03:55 UTC
    CWE
    • RCE (Remote Code Execution)
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: 8.9.0
    Affected: 8.8.0 to 8.8.1
    Affected: 8.7.1 to 8.7.2
    Affected: 8.6.0 to 8.6.2
    Affected: 8.5.0 to 8.5.8
    Affected: 8.4.0 to 8.4.5
    Affected: 8.3.0 to 8.3.4
    Affected: 8.2.0 to 8.2.3
    Affected: 8.1.0 to 8.1.4
    Affected: 8.0.0 to 8.0.4
    Affected: 7.20.0 to 7.20.3
    Affected: 7.19.0 to 7.19.21
    Unaffected: 8.9.1 to 8.9.2
    Unaffected: 8.5.9 to 8.5.10
    Unaffected: 7.19.22 to 7.19.23
    Create a notification for this product.
    atlassian confluence_data_center Affected: 8.9.0
    Affected: 8.8.0 , ≤ 8.8.1 (custom)
    Affected: 8.7.1 , ≤ 8.7.2 (custom)
    Affected: 8.6.0 , ≤ 8.6.2 (custom)
    Affected: 8.5.0 , ≤ 8.5.8 (custom)
    Affected: 8.4.0 , ≤ 8.4.5 (custom)
    Affected: 8.3.0 , ≤ 8.3.4 (custom)
    Affected: 8.2.0 , ≤ 8.2.3 (custom)
    Affected: 8.1.0 , ≤ 8.1.4 (custom)
    Affected: 8.0.0 , ≤ 8.0.4 (custom)
    Affected: 7.20.0 , ≤ 7.20.3 (custom)
    Affected: 7.19.0 , ≤ 7.1921 (custom)
    Affected: 8.9.1
    Affected: 8.5.9
    Affected: 7.19.22
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.9.0"
                  },
                  {
                    "lessThanOrEqual": "8.8.1",
                    "status": "affected",
                    "version": "8.8.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.7.2",
                    "status": "affected",
                    "version": "8.7.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.6.2",
                    "status": "affected",
                    "version": "8.6.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.5.8",
                    "status": "affected",
                    "version": "8.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.4.5",
                    "status": "affected",
                    "version": "8.4.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.3.4",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.2.3",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.1.4",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "8.0.4",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.20.3",
                    "status": "affected",
                    "version": "7.20.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "7.1921",
                    "status": "affected",
                    "version": "7.19.0",
                    "versionType": "custom"
                  },
                  {
                    "status": "affected",
                    "version": "8.9.1"
                  },
                  {
                    "status": "affected",
                    "version": "8.5.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.19.22"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21683",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-20T03:55:34.077361Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-12T15:22:41.587Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "affected",
                  "version": "8.9.0"
                },
                {
                  "status": "affected",
                  "version": "8.8.0 to 8.8.1"
                },
                {
                  "status": "affected",
                  "version": "8.7.1 to 8.7.2"
                },
                {
                  "status": "affected",
                  "version": "8.6.0 to 8.6.2"
                },
                {
                  "status": "affected",
                  "version": "8.5.0 to 8.5.8"
                },
                {
                  "status": "affected",
                  "version": "8.4.0 to 8.4.5"
                },
                {
                  "status": "affected",
                  "version": "8.3.0 to 8.3.4"
                },
                {
                  "status": "affected",
                  "version": "8.2.0 to 8.2.3"
                },
                {
                  "status": "affected",
                  "version": "8.1.0 to 8.1.4"
                },
                {
                  "status": "affected",
                  "version": "8.0.0 to 8.0.4"
                },
                {
                  "status": "affected",
                  "version": "7.20.0 to 7.20.3"
                },
                {
                  "status": "affected",
                  "version": "7.19.0 to 7.19.21"
                },
                {
                  "status": "unaffected",
                  "version": "8.9.1 to 8.9.2"
                },
                {
                  "status": "unaffected",
                  "version": "8.5.9 to 8.5.10"
                },
                {
                  "status": "unaffected",
                  "version": "7.19.22 to 7.19.23"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Atlassian"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.\n\nThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.\u00a0\n\nAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html\n\nYou can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives.\n\nThis vulnerability was found internally."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "RCE (Remote Code Execution)",
                  "lang": "en",
                  "type": "RCE (Remote Code Execution)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-14T20:55:38.532Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1409286211"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-95832"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2024-21683",
        "datePublished": "2024-05-21T23:00:00.446Z",
        "dateReserved": "2024-01-01T00:05:33.846Z",
        "dateUpdated": "2025-05-12T15:22:41.587Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21677 (GCVE-0-2024-21677)

    Vulnerability from cvelistv5 – Published: 2024-03-19 17:00 – Updated: 2025-03-13 17:39
    VLAI
    Summary
    This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Data Center Atlassian recommends that Confluence Data Center customers upgrade to the latest version and that Confluence Server customers upgrade to the latest 8.5.x LTS version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html You can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives. This vulnerability was reported via our Bug Bounty program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-10 04:00 UTC
    CWE
    • Other
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 6.13.0
    Affected: >= 6.13.0
    Affected: >= 7.19.0
    Affected: >= 7.20.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.6.0
    Affected: >= 8.7.1
    Affected: >= 8.8.0
    Unaffected: >= 7.19.20
    Unaffected: >= 8.5.7
    Unaffected: >= 8.8.1
    Create a notification for this product.
    atlassian confluence_data_center Affected: 8.8.0
        cpe:2.3:a:atlassian:confluence_data_center:8.8.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 7.19.0 , < 7.19.19 (custom)
    Affected: 7.20.0 , < 7.20.3 (custom)
    Affected: 8.0.0 , < 8.0.4 (custom)
    Affected: 8.1.0 , < 8.1.4 (custom)
    Affected: 8.2.0 , < 8.2.3 (custom)
    Affected: 8.3.0 , < 8.3.4 (custom)
    Affected: 8.4.0 , < 8.4.5 (custom)
    Affected: 8.5 , < 8.5.6 (custom)
    Affected: 8.6.0 , < 8.6.2 (custom)
    Affected: 8.7.0 , < 8.7.2 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:8.7.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:7.19.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:7.20.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.1.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.2.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.3.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.4.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.5:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:8.6.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 7.17.0 , < 7.17.5 (custom)
    Affected: 7.18.0 , < 7.18.3 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:7.17.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 0 , < 7.17.0 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:8.8.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.8.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:8.7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:7.19.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:7.20.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:8.0.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:8.1.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:8.2.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:8.3.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:8.4.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:8.5:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:8.6.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.19.19",
                    "status": "affected",
                    "version": "7.19.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.20.3",
                    "status": "affected",
                    "version": "7.20.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.0.4",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.1.4",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.2.3",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.3.4",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.4.5",
                    "status": "affected",
                    "version": "8.4.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.5.6",
                    "status": "affected",
                    "version": "8.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.6.2",
                    "status": "affected",
                    "version": "8.6.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.7.2",
                    "status": "affected",
                    "version": "8.7.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:7.17.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.17.5",
                    "status": "affected",
                    "version": "7.17.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.18.3",
                    "status": "affected",
                    "version": "7.18.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.17.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21677",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-10T04:00:27.568364Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-13T17:39:21.647Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T22:27:35.969Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1369444862"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-94604"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 6.13.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 6.13.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.20.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.7.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.8.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.20"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.7"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.8.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.\n\nAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Data Center Atlassian recommends that Confluence Data Center customers upgrade to the latest version and that Confluence Server customers upgrade to the latest 8.5.x LTS version.\n\nIf you are unable to do so, upgrade your instance to one of the specified supported fixed versions See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html\n\nYou can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives. \n\nThis vulnerability was reported via our Bug Bounty program."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Other",
                  "lang": "en",
                  "type": "Other"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-19T17:30:00.500Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1369444862"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-94604"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2024-21677",
        "datePublished": "2024-03-19T17:00:00.486Z",
        "dateReserved": "2024-01-01T00:05:33.846Z",
        "dateUpdated": "2025-03-13T17:39:21.647Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21678 (GCVE-0-2024-21678)

    Vulnerability from cvelistv5 – Published: 2024-02-20 18:00 – Updated: 2024-10-31 15:16
    VLAI
    Summary
    This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, low impact to integrity, no impact to availability, and requires no user interaction. Data Center Atlassian recommends that Confluence Data Center customers upgrade to the latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions: ||Affected versions||Fixed versions|| |from 8.7.0 to 8.7.1|8.8.0 recommended or 8.7.2| |from 8.6.0 to 8.6.1|8.8.0 recommended| |from 8.5.0 to 8.5.4 LTS|8.8.0 recommended or 8.5.5 LTS or 8.5.6 LTS| |from 8.4.0 to 8.4.5|8.8.0 recommended or 8.5.6 LTS| |from 8.3.0 to 8.3.4|8.8.0 recommended or 8.5.6 LTS| |from 8.2.0 to 8.2.3|8.8.0 recommended or 8.5.6 LTS| |from 8.1.0 to 8.1.4|8.8.0 recommended or 8.5.6 LTS| |from 8.0.0 to 8.0.4|8.8.0 recommended or 8.5.6 LTS| |from 7.20.0 to 7.20.3|8.8.0 recommended or 8.5.6 LTS| |from 7.19.0 to 7.19.17 LTS|8.8.0 recommended or 8.5.6 LTS or 7.19.18 LTS or 7.19.19 LTS| |from 7.18.0 to 7.18.3|8.8.0 recommended or 8.5.6 LTS or 7.19.19 LTS| |from 7.17.0 to 7.17.5|8.8.0 recommended or 8.5.6 LTS or 7.19.19 LTS| |Any earlier versions|8.8.0 recommended or 8.5.6 LTS or 7.19.19 LTS| Server Atlassian recommends that Confluence Server customers upgrade to the latest 8.5.x LTS version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions:   ||Affected versions||Fixed versions|| |from 8.5.0 to 8.5.4 LTS|8.5.5 LTS or 8.5.6 LTS recommended | |from 8.4.0 to 8.4.5|8.5.6 LTS recommended| |from 8.3.0 to 8.3.4|8.5.6 LTS recommended| |from 8.2.0 to 8.2.3|8.5.6 LTS recommended| |from 8.1.0 to 8.1.4|8.5.6 LTS recommended| |from 8.0.0 to 8.0.4|8.5.6 LTS recommended| |from 7.20.0 to 7.20.3|8.5.6 LTS recommended| |from 7.19.0 to 7.19.17 LTS|8.5.6 LTS recommended or 7.19.18 LTS or 7.19.19 LTS| |from 7.18.0 to 7.18.3|8.5.6 LTS recommended or 7.19.19 LTS| |from 7.17.0 to 7.17.5|8.5.6 LTS recommended or 7.19.19 LTS| |Any earlier versions|8.5.6 LTS recommended or 7.19.19 LTS| See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Bug Bounty program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-02-21 18:49 UTC
    CWE
    • Stored XSS
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 2.7.0
    Affected: >= 2.7.0
    Affected: >= 7.13.0
    Affected: >= 7.19.0
    Affected: >= 7.20.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.6.0
    Affected: >= 8.7.1
    Unaffected: >= 7.19.18
    Unaffected: >= 8.5.5
    Unaffected: >= 8.7.2
    Unaffected: >= 8.8.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21678",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-02-21T18:49:48.543984Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-79",
                    "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-31T15:16:18.788Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T22:27:35.810Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1354501606"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-94513"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 2.7.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 2.7.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.13.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.20.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.7.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.18"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.5"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.7.2"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.8.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center.\r\n\r\nThis Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, low impact to integrity, no impact to availability, and requires no user interaction.\r\nData Center\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to the latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n||Affected versions||Fixed versions||\r\n|from 8.7.0 to 8.7.1|8.8.0 recommended or 8.7.2|\r\n|from 8.6.0 to 8.6.1|8.8.0 recommended|\r\n|from 8.5.0 to 8.5.4 LTS|8.8.0 recommended or 8.5.5 LTS or 8.5.6 LTS|\r\n|from 8.4.0 to 8.4.5|8.8.0 recommended or 8.5.6 LTS|\r\n|from 8.3.0 to 8.3.4|8.8.0 recommended or 8.5.6 LTS|\r\n|from 8.2.0 to 8.2.3|8.8.0 recommended or 8.5.6 LTS|\r\n|from 8.1.0 to 8.1.4|8.8.0 recommended or 8.5.6 LTS|\r\n|from 8.0.0 to 8.0.4|8.8.0 recommended or 8.5.6 LTS|\r\n|from 7.20.0 to 7.20.3|8.8.0 recommended or 8.5.6 LTS|\r\n|from 7.19.0 to 7.19.17 LTS|8.8.0 recommended or 8.5.6 LTS or 7.19.18 LTS or 7.19.19 LTS|\r\n|from 7.18.0 to 7.18.3|8.8.0 recommended or 8.5.6 LTS or 7.19.19 LTS|\r\n|from 7.17.0 to 7.17.5|8.8.0 recommended or 8.5.6 LTS or 7.19.19 LTS|\r\n|Any earlier versions|8.8.0 recommended or 8.5.6 LTS or 7.19.19 LTS|\r\nServer\r\n\r\nAtlassian recommends that Confluence Server customers upgrade to the latest 8.5.x LTS version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n\r\n\u00a0\r\n||Affected versions||Fixed versions||\r\n|from 8.5.0 to 8.5.4 LTS|8.5.5 LTS or 8.5.6 LTS recommended\u00a0|\r\n|from 8.4.0 to 8.4.5|8.5.6 LTS recommended|\r\n|from 8.3.0 to 8.3.4|8.5.6 LTS recommended|\r\n|from 8.2.0 to 8.2.3|8.5.6 LTS recommended|\r\n|from 8.1.0 to 8.1.4|8.5.6 LTS recommended|\r\n|from 8.0.0 to 8.0.4|8.5.6 LTS recommended|\r\n|from 7.20.0 to 7.20.3|8.5.6 LTS recommended|\r\n|from 7.19.0 to 7.19.17 LTS|8.5.6 LTS recommended or 7.19.18 LTS or 7.19.19 LTS|\r\n|from 7.18.0 to 7.18.3|8.5.6 LTS recommended or 7.19.19 LTS|\r\n|from 7.17.0 to 7.17.5|8.5.6 LTS recommended or 7.19.19 LTS|\r\n|Any earlier versions|8.5.6 LTS recommended or 7.19.19 LTS|\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Bug Bounty program."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Stored XSS",
                  "lang": "en",
                  "type": "Stored XSS"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-20T18:00:00.727Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1354501606"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-94513"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2024-21678",
        "datePublished": "2024-02-20T18:00:00.727Z",
        "dateReserved": "2024-01-01T00:05:33.846Z",
        "dateUpdated": "2024-10-31T15:16:18.788Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21673 (GCVE-0-2024-21673)

    Vulnerability from cvelistv5 – Published: 2024-01-16 05:00 – Updated: 2025-06-03 18:47
    VLAI
    Summary
    This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and does not require user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release * Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release * Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ).
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-01-25 05:00 UTC
    CWE
    • RCE (Remote Code Execution)
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 7.13.0
    Affected: >= 7.13.0
    Affected: >= 7.19.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.6.0
    Affected: >= 8.7.1
    Unaffected: >= 7.19.18
    Unaffected: >= 8.5.5
    Unaffected: >= 8.7.2
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 7.13.0
    Affected: >= 7.13.0
    Affected: >= 7.19.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.6.0
    Affected: >= 8.7.1
    Unaffected: >= 7.19.18
    Unaffected: >= 8.5.5
    Create a notification for this product.
    atlassian confluence_data_center Affected: 0 , < 8.7.2 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:-:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 0 , < 8.7.1 (custom)
        cpe:2.3:a:atlassian:confluence_server:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T22:27:36.035Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-94065"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.7.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.7.1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21673",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-25T05:00:56.340614Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-03T18:47:43.178Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 7.13.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.13.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.7.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.18"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.5"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.7.2"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 7.13.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.13.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.7.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.18"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "xiaoc"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server.\n\nRemote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of\u00a0CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and does not require user interaction.\n\nAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\n* Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release\n* Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release\n* Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release\n\nSee the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives )."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "RCE (Remote Code Execution)",
                  "lang": "en",
                  "type": "RCE (Remote Code Execution)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-16T18:00:00.463Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-94065"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2024-21673",
        "datePublished": "2024-01-16T05:00:00.724Z",
        "dateReserved": "2024-01-01T00:05:33.845Z",
        "dateUpdated": "2025-06-03T18:47:43.178Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21672 (GCVE-0-2024-21672)

    Vulnerability from cvelistv5 – Published: 2024-01-16 05:00 – Updated: 2025-06-02 15:12
    VLAI
    Summary
    This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release * Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release * Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives).
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-08 15:47 UTC
    CWE
    • RCE (Remote Code Execution)
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 7.19.0
    Affected: >= 7.19.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.6.0
    Affected: >= 8.7.1
    Unaffected: >= 7.19.18
    Unaffected: >= 8.5.5
    Unaffected: >= 8.7.2
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 7.19.0
    Affected: >= 7.19.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.6.0
    Affected: >= 8.7.1
    Unaffected: >= 7.19.18
    Unaffected: >= 8.5.5
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T22:27:35.887Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-94064"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21672",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-08T15:47:09.230689Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-02T15:12:12.778Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.7.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.18"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.5"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.7.2"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.7.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.18"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "DDV_UA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server.\n\nRemote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of\u00a0CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.\n\nAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\n* Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release\n* Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release\n* Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release\n\nSee the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives)."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "RCE (Remote Code Execution)",
                  "lang": "en",
                  "type": "RCE (Remote Code Execution)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-17T01:00:01.127Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-94064"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2024-21672",
        "datePublished": "2024-01-16T05:00:00.703Z",
        "dateReserved": "2024-01-01T00:05:33.845Z",
        "dateUpdated": "2025-06-02T15:12:12.778Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22527 (GCVE-0-2023-22527)

    Vulnerability from cvelistv5 – Published: 2024-01-16 05:00 – Updated: 2025-10-21 23:05
    VLAI
    Summary
    A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-02-14 05:00 UTC
    CWE
    • RCE (Remote Code Execution)
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 8.0.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.5.1
    Affected: >= 8.5.2
    Affected: >= 8.5.3
    Unaffected: >= 8.5.4
    Unaffected: >= 8.6.0
    Unaffected: >= 8.7.1
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 8.0.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.5.1
    Affected: >= 8.5.2
    Affected: >= 8.5.3
    Unaffected: >= 8.5.4
    Unaffected: >= 8.6.0
    Create a notification for this product.
    atlassian confluence_data_center Affected: 8.0.0 , < 8.5.4 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:8.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 8.0.0 , < 8.5.4 (custom)
        cpe:2.3:a:atlassian:confluence_server:8.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:8.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.5.4",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:8.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.5.4",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22527",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-02-14T05:00:58.661097Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2024-01-24",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22527"
                  },
                  "type": "kev"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-74",
                    "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:05:28.527Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22527"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2024-01-24T00:00:00.000Z",
                "value": "CVE-2023-22527 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-19T07:47:54.708Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1333335615"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-93833"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/176789/Atlassian-Confluence-SSTI-Injection.html"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/pwning-confluence-via-ognl-injection-for-fun-and-learning-cve-2023-22527"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.3"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.4"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.7.1"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.3"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.4"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.6.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Petrus Viet"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.\n\nMost recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian\u2019s January Security Bulletin."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "RCE (Remote Code Execution)",
                  "lang": "en",
                  "type": "RCE (Remote Code Execution)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-26T17:06:21.681Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1333335615"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-93833"
            },
            {
              "url": "http://packetstormsecurity.com/files/176789/Atlassian-Confluence-SSTI-Injection.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22527",
        "datePublished": "2024-01-16T05:00:00.692Z",
        "dateReserved": "2023-01-01T00:01:22.333Z",
        "dateUpdated": "2025-10-21T23:05:28.527Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-21674 (GCVE-0-2024-21674)

    Vulnerability from cvelistv5 – Published: 2024-01-16 05:00 – Updated: 2024-08-29 14:38
    VLAI
    Summary
    This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, no impact to integrity, no impact to availability, and does not require user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release * Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release * Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ).
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-29 14:37 UTC
    CWE
    • RCE (Remote Code Execution)
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 7.19.0
    Affected: >= 7.19.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.6.0
    Affected: >= 8.7.1
    Unaffected: >= 7.19.18
    Unaffected: >= 8.5.5
    Unaffected: >= 8.7.2
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 7.19.0
    Affected: >= 7.19.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.6.0
    Affected: >= 8.7.1
    Unaffected: >= 7.19.18
    Unaffected: >= 8.5.5
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T22:27:36.170Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-94066"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-21674",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-29T14:37:34.659948Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-29T14:38:32.248Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.7.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.18"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.5"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.7.2"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.7.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.18"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "DDV_UA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server.\n\nRemote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, no impact to integrity, no impact to availability, and does not require user interaction.\n\nAtlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\n* Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release\n* Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release\n* Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release\n\nSee the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives )."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "RCE (Remote Code Execution)",
                  "lang": "en",
                  "type": "RCE (Remote Code Execution)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-16T17:00:02.134Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-94066"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2024-21674",
        "datePublished": "2024-01-16T05:00:00.639Z",
        "dateReserved": "2024-01-01T00:05:33.845Z",
        "dateUpdated": "2024-08-29T14:38:32.248Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22526 (GCVE-0-2023-22526)

    Vulnerability from cvelistv5 – Published: 2024-01-16 05:00 – Updated: 2025-06-20 17:01
    VLAI
    Summary
    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 7.19: Upgrade to a release 7.19.17, or any higher 7.19.x release Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was discovered by m1sn0w and reported via our Bug Bounty program
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-01-25 05:00 UTC
    CWE
    • RCE (Remote Code Execution)
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 7.13.0
    Affected: >= 7.13.0
    Affected: >= 7.19.0
    Affected: >= 8.0.0
    Affected: >= 8.1.0
    Affected: >= 8.2.0
    Affected: >= 8.3.0
    Affected: >= 8.4.0
    Affected: >= 8.5.0
    Affected: >= 8.6.0
    Affected: >= 8.7.1
    Unaffected: >= 7.19.17
    Unaffected: >= 8.5.5
    Unaffected: >= 8.7.2
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:13:48.994Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1333335615"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-93516"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22526",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-25T05:00:53.918669Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-20T17:01:17.956Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 7.13.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.13.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.19.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.7.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.17"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.5"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.7.2"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "m1sn0w"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center.\r\n\r\nThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center and Server 7.19: Upgrade to a release 7.19.17, or any higher 7.19.x release\r\n Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release\r\n Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was discovered by m1sn0w and reported via our Bug Bounty program"
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "RCE (Remote Code Execution)",
                  "lang": "en",
                  "type": "RCE (Remote Code Execution)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-16T18:00:00.754Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1333335615"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-93516"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22526",
        "datePublished": "2024-01-16T05:00:00.597Z",
        "dateReserved": "2023-01-01T00:01:22.333Z",
        "dateUpdated": "2025-06-20T17:01:17.956Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22522 (GCVE-0-2023-22522)

    Vulnerability from cvelistv5 – Published: 2023-12-06 05:00 – Updated: 2026-02-25 16:52
    VLAI
    Summary
    This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server versions as listed below are at risk and require immediate attention. See the advisory for additional details Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2023-12-07 05:00 UTC
    CWE
    • RCE (Remote Code Execution)
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 4.0.0
    Affected: >= 4.0.0
    Affected: >= 7.20.0
    Affected: >= 8.0.0
    Affected: >= 8.6.0
    Unaffected: >= 7.19.17
    Unaffected: >= 8.4.5
    Unaffected: >= 8.5.4
    Unaffected: >= 8.6.2
    Unaffected: >= 8.7.1
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 4.0.0
    Affected: >= 4.0.0
    Affected: >= 7.20.0
    Affected: >= 8.0.0
    Affected: >= 8.6.0
    Unaffected: >= 7.19.17
    Unaffected: >= 8.4.5
    Unaffected: >= 8.5.4
    Unaffected: >= 8.6.2
    Unaffected: >= 8.7.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:13:48.928Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1319570362"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-93502"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22522",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2023-12-07T05:00:08.839200Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-74",
                    "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-25T16:52:11.981Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 4.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 4.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.20.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.17"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.4.5"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.4"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.6.2"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.7.1"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 4.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 4.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.20.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.6.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.17"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.4.5"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.4"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.6.2"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.7.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server versions as listed below are at risk and require immediate attention. See the advisory for additional details\n\nAtlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "RCE (Remote Code Execution)",
                  "lang": "en",
                  "type": "RCE (Remote Code Execution)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-12-06T21:00:01.250Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1319570362"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-93502"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22522",
        "datePublished": "2023-12-06T05:00:02.870Z",
        "dateReserved": "2023-01-01T00:01:22.333Z",
        "dateUpdated": "2026-02-25T16:52:11.981Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-22518 (GCVE-0-2023-22518)

    Vulnerability from cvelistv5 – Published: 2023-10-31 14:30 – Updated: 2025-10-21 23:05
    VLAI
    Summary
    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-03 16:33 UTC
    CWE
    • Improper Authorization
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 1.0.0
    Affected: >= 1.0.0
    Unaffected: >= 7.19.16
    Unaffected: >= 8.3.4
    Unaffected: >= 8.4.4
    Unaffected: >= 8.5.3
    Unaffected: >= 8.6.1
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 1.0.0
    Affected: >= 1.0.0
    Unaffected: >= 7.19.16
    Unaffected: >= 8.3.4
    Unaffected: >= 8.4.4
    Unaffected: >= 8.5.3
    Unaffected: >= 8.6.1
    Create a notification for this product.
    Credits
    -
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:13:48.670Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1311473907"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-93142"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/176264/Atlassian-Confluence-Improper-Authorization-Code-Execution.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22518",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-03T16:33:26.216427Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2023-11-07",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22518"
                  },
                  "type": "kev"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-863",
                    "description": "CWE-863 Incorrect Authorization",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:05:32.975Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22518"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2023-11-07T00:00:00.000Z",
                "value": "CVE-2023-22518 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 1.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 1.0.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.16"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.3.4"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.4.4"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.3"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.6.1"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 1.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 1.0.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.16"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.3.4"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.4.4"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.3"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.6.1"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "-"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to\u00a0Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.\u00a0\n\nAtlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Authorization",
                  "lang": "en",
                  "type": "Improper Authorization"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-12-19T16:06:15.741Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1311473907"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-93142"
            },
            {
              "url": "http://packetstormsecurity.com/files/176264/Atlassian-Confluence-Improper-Authorization-Code-Execution.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22518",
        "datePublished": "2023-10-31T14:30:00.418Z",
        "dateReserved": "2023-01-01T00:01:22.332Z",
        "dateUpdated": "2025-10-21T23:05:32.975Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22515 (GCVE-0-2023-22515)

    Vulnerability from cvelistv5 – Published: 2023-10-04 14:00 – Updated: 2026-03-25 14:56
    VLAI
    Summary
    Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2023-12-09 05:05 UTC
    CWE
    • BASM (Broken Authentication & Session Management)
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 8.0.0
    Affected: >= 8.0.0
    Affected: >= 8.0.1
    Affected: >= 8.0.2
    Affected: >= 8.0.3
    Affected: >= 8.1.3
    Affected: >= 8.1.4
    Affected: >= 8.2.0
    Affected: >= 8.2.1
    Affected: >= 8.2.2
    Affected: >= 8.2.3
    Affected: >= 8.3.0
    Affected: >= 8.3.1
    Affected: >= 8.3.2
    Affected: >= 8.4.0
    Affected: >= 8.4.1
    Affected: >= 8.4.2
    Affected: >= 8.5.0
    Affected: >= 8.5.1
    Unaffected: >= 8.3.3
    Unaffected: >= 8.4.3
    Unaffected: >= 8.5.2
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 8.0.0
    Affected: >= 8.0.0
    Affected: >= 8.0.1
    Affected: >= 8.0.2
    Affected: >= 8.0.3
    Affected: >= 8.1.3
    Affected: >= 8.1.4
    Affected: >= 8.2.0
    Affected: >= 8.2.1
    Affected: >= 8.2.2
    Affected: >= 8.2.3
    Affected: >= 8.3.0
    Affected: >= 8.3.1
    Affected: >= 8.3.2
    Affected: >= 8.4.0
    Affected: >= 8.4.1
    Affected: >= 8.4.2
    Affected: >= 8.5.0
    Affected: >= 8.5.1
    Unaffected: >= 8.3.3
    Unaffected: >= 8.4.3
    Unaffected: >= 8.5.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:13:48.693Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/175225/Atlassian-Confluence-Unauthenticated-Remote-Code-Execution.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-92475"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22515",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2023-12-09T05:05:17.297744Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2023-10-05",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22515"
                  },
                  "type": "kev"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-20",
                    "description": "CWE-20 Improper Input Validation",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-25T14:56:37.404Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22515"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.3"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.3"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.4"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.3"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.3.3"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.4.3"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.2"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.3"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.3"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.1.4"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.2.3"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.3.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.1"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.4.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.5.1"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.3.3"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.4.3"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.5.2"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "an Atlassian customer"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. \r\n\r\nAtlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "BASM (Broken Authentication \u0026 Session Management)",
                  "lang": "en",
                  "type": "BASM (Broken Authentication \u0026 Session Management)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-20T16:00:01.026Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "http://packetstormsecurity.com/files/175225/Atlassian-Confluence-Unauthenticated-Remote-Code-Execution.html"
            },
            {
              "url": "https://confluence.atlassian.com/display/KB/FAQ+for+CVE-2023-22515"
            },
            {
              "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1295682276"
            },
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-92475"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22515",
        "datePublished": "2023-10-04T14:00:00.820Z",
        "dateReserved": "2023-01-01T00:01:22.331Z",
        "dateUpdated": "2026-03-25T14:56:37.404Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-22508 (GCVE-0-2023-22508)

    Vulnerability from cvelistv5 – Published: 2023-07-18 23:00 – Updated: 2024-08-02 10:13
    VLAI
    Summary
    This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that you upgrade your instance to avoid this bug using the following options: * Upgrade to a Confluence feature release greater than or equal to 8.2.0 (ie: 8.2, 8.2, 8.4, etc...) * Upgrade to a Confluence 7.19 LTS bugfix release greater than or equal to 7.19.8 (ie: 7.19.8, 7.19.9, 7.19.10, 7.19.11, etc...) * Upgrade to a Confluence 7.13 LTS bugfix release greater than or equal to 7.13.20 (Release available early August) See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Data Center & Server from the download center (https://www.atlassian.com/software/confluence/download-archives ). If you are unable to upgrade your instance please use the following guide to workaround the issue https://confluence.atlassian.com/confkb/how-to-disable-the-jmx-network-port-for-cve-2023-22508-1267761550.html This vulnerability was discovered by a private user and reported via our Bug Bounty program.
    CWE
    • RCE (Remote Code Execution)
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 6.1.0
    Affected: >= 6.1.0
    Unaffected: >= 7.19.8
    Unaffected: >= 8.2.0
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 6.1.0
    Affected: >= 6.1.0
    Unaffected: >= 7.19.8
    Unaffected: >= 8.2.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:13:48.922Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-88221"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 6.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 6.1.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.8"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.2.0"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 6.1.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 6.1.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.8"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.2.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "a private user"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center \u0026 Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that you upgrade your instance to avoid this bug using the following options: * Upgrade to a Confluence feature release greater than or equal to 8.2.0 (ie: 8.2, 8.2, 8.4, etc...) * Upgrade to a Confluence 7.19 LTS bugfix release greater than or equal to 7.19.8 (ie: 7.19.8, 7.19.9, 7.19.10, 7.19.11, etc...) * Upgrade to a Confluence 7.13 LTS bugfix release greater than or equal to 7.13.20 (Release available early August) See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Data Center \u0026 Server from the download center (https://www.atlassian.com/software/confluence/download-archives ). If you are unable to upgrade your instance please use the following guide to workaround the issue https://confluence.atlassian.com/confkb/how-to-disable-the-jmx-network-port-for-cve-2023-22508-1267761550.html This vulnerability was discovered by a private user and reported via our Bug Bounty program."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "RCE (Remote Code Execution)",
                  "lang": "en",
                  "type": "RCE (Remote Code Execution)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-28T17:00:01.069Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-88221"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22508",
        "datePublished": "2023-07-18T23:00:00.725Z",
        "dateReserved": "2023-01-01T00:01:22.330Z",
        "dateUpdated": "2024-08-02T10:13:48.922Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22505 (GCVE-0-2023-22505)

    Vulnerability from cvelistv5 – Published: 2023-07-18 21:00 – Updated: 2024-10-01 16:57
    VLAI
    Summary
    This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that you upgrade your instance to latest version. If you're unable to upgrade to latest, upgrade to one of these fixed versions: 8.3.2, 8.4.0. See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html).|https://confluence.atlassian.com/doc/confluence-release-notes-327.html).] You can download the latest version of Confluence Data Center & Server from the download center ([https://www.atlassian.com/software/confluence/download-archives).|https://www.atlassian.com/software/confluence/download-archives).] This vulnerability was discovered by a private user and reported via our Bug Bounty program.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 16:34 UTC
    CWE
    • RCE (Remote Code Execution)
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 8.0.0
    Affected: >= 8.0.0
    Unaffected: >= 8.3.2
    Unaffected: >= 8.4.0
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 8.0.0
    Affected: >= 8.0.0
    Unaffected: >= 8.3.2
    Unaffected: >= 8.4.0
    Create a notification for this product.
    atlassian confluence_data_center Affected: 8.0.0 , < 8.3.2 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 8.0.0 , < 8.3.2 (custom)
        cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:13:48.555Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-88265"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.3.2",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.3.2",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22505",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T16:34:34.966748Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T16:57:28.043Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.3.2"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.4.0"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 8.0.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 8.0.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.3.2"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.4.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "a private user"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center \u0026 Server.\n\nThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction.\n\nAtlassian recommends that you upgrade your instance to latest version. If you\u0027re unable to upgrade to latest, upgrade to one of these fixed versions: 8.3.2, 8.4.0. See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html).|https://confluence.atlassian.com/doc/confluence-release-notes-327.html).]  You can download the latest version of Confluence Data Center \u0026 Server from the download center ([https://www.atlassian.com/software/confluence/download-archives).|https://www.atlassian.com/software/confluence/download-archives).] \n\nThis vulnerability was discovered by a private user and reported via our Bug Bounty program."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "RCE (Remote Code Execution)",
                  "lang": "en",
                  "type": "RCE (Remote Code Execution)"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-18T21:00:00.968Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-88265"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22505",
        "datePublished": "2023-07-18T21:00:00.968Z",
        "dateReserved": "2023-01-01T00:01:22.329Z",
        "dateUpdated": "2024-10-01T16:57:28.043Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22504 (GCVE-0-2023-22504)

    Vulnerability from cvelistv5 – Published: 2023-05-25 14:00 – Updated: 2024-10-01 15:23
    VLAI
    Summary
    Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 15:23 UTC
    CWE
    • Improper Authorization
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 1.1.2
    Affected: >= 1.1.2
    Affected: >= 7.14.0
    Affected: >= 7.20.0
    Unaffected: >= 7.13.7
    Unaffected: >= 7.19.9
    Unaffected: >= 8.2.2
    Unaffected: >= 8.3.0
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 1.1.2
    Affected: >= 1.1.2
    Affected: >= 7.14.0
    Affected: >= 7.20.0
    Unaffected: >= 7.13.7
    Unaffected: >= 7.19.9
    Unaffected: >= 8.2.2
    Unaffected: >= 8.3.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:13:48.544Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-83218"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22504",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T15:23:16.949639Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T15:23:29.330Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 1.1.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 1.1.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.14.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.20.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.13.7"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.9"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.2.2"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.3.0"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 1.1.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 1.1.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.14.0"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.20.0"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.13.7"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.9"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.2.2"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.3.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "This vulnerability was discovered by Rojan Rijal of the Tinder Security Engineering Team."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Authorization",
                  "lang": "en",
                  "type": "Improper Authorization"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-06-07T14:00:01.151Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-83218"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22504",
        "datePublished": "2023-05-25T14:00:02.234Z",
        "dateReserved": "2023-01-01T00:01:22.329Z",
        "dateUpdated": "2024-10-01T15:23:29.330Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-22503 (GCVE-0-2023-22503)

    Vulnerability from cvelistv5 – Published: 2023-05-01 16:00 – Updated: 2024-10-01 15:22
    VLAI
    Summary
    Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team. The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-01 15:14 UTC
    CWE
    • Information Disclosure
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Unaffected: < 7.20.2
    Affected: >= 7.20.2
    Unaffected: >= 7.13.5
    Unaffected: >= 7.19.7
    Unaffected: >= 8.20.0
    Create a notification for this product.
    Atlassian Confluence Server Unaffected: < 7.20.2
    Affected: >= 7.20.2
    Unaffected: >= 7.13.5
    Unaffected: >= 7.19.7
    Unaffected: >= 8.20.0
    Create a notification for this product.
    atlassian confluence_data_center Affected: 0 , < 7.13.15 (custom)
    Affected: 7.14.0 , < 7.19.7 (custom)
    Affected: 7.20.0 , < 8.2.0 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 0 , < 7.13.15 (custom)
    Affected: 7.14.0 , < 7.19.7 (custom)
    Affected: 7.20.0 , < 8.2.0 (custom)
        cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T10:13:48.665Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-82403"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.13.15",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.19.7",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.2.0",
                    "status": "affected",
                    "version": "7.20.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.13.15",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.19.7",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.2.0",
                    "status": "affected",
                    "version": "7.20.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-22503",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-01T15:14:47.693093Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-200",
                    "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-01T15:22:41.837Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 7.20.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.20.2"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.13.5"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.7"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.20.0"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "status": "unaffected",
                  "version": "\u003c 7.20.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 7.20.2"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.13.5"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 7.19.7"
                },
                {
                  "status": "unaffected",
                  "version": "\u003e= 8.20.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.\r\n\r\nThis vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.\r\n\r\nThe affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "Information Disclosure"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-01T16:00:32.509Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "url": "https://jira.atlassian.com/browse/CONFSERVER-82403"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2023-22503",
        "datePublished": "2023-05-01T16:00:32.509Z",
        "dateReserved": "2023-01-01T00:01:22.329Z",
        "dateUpdated": "2024-10-01T15:22:41.837Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-36290 (GCVE-0-2020-36290)

    Vulnerability from cvelistv5 – Published: 2022-07-26 04:05 – Updated: 2024-10-03 18:36
    VLAI
    Summary
    The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-03 18:36 UTC
    CWE
    • Cross Site Scripting (XSS)
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Server Affected: unspecified , < 7.4.5 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.6.3 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: unspecified , < 7.7.4 (custom)
    Create a notification for this product.
    Atlassian Confluence Data Center Affected: unspecified , < 7.4.5 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.6.3 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: unspecified , < 7.7.4 (custom)
    Create a notification for this product.
    Date Public
    2022-07-26 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T17:23:09.942Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-60118"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-36290",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-03T18:36:19.960463Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-03T18:36:30.272Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.6.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.7.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.6.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.7.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-07-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Cross Site Scripting (XSS)",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-26T04:05:14.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CONFSERVER-60118"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2022-07-26T00:00:00",
              "ID": "CVE-2020-36290",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Confluence Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.7.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.7.4"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Cross Site Scripting (XSS)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CONFSERVER-60118",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CONFSERVER-60118"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2020-36290",
        "datePublished": "2022-07-26T04:05:14.704Z",
        "dateReserved": "2021-03-31T00:00:00.000Z",
        "dateUpdated": "2024-10-03T18:36:30.272Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-26137 (GCVE-0-2022-26137)

    Vulnerability from cvelistv5 – Published: 2022-07-20 17:25 – Updated: 2024-10-03 17:10
    VLAI
    Summary
    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-03 16:48 UTC
    CWE
    • CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize (CWE-180)
    Impacted products
    Vendor Product Version
    Atlassian Bamboo Server Affected: unspecified , < 8.0.9 (custom)
    Affected: 8.1.0 , < unspecified (custom)
    Affected: unspecified , < 8.1.8 (custom)
    Affected: 8.2.0 , < unspecified (custom)
    Affected: unspecified , < 8.2.4 (custom)
    Create a notification for this product.
    Atlassian Bamboo Data Center Affected: unspecified , < 8.0.9 (custom)
    Affected: 8.1.0 , < unspecified (custom)
    Affected: unspecified , < 8.1.8 (custom)
    Affected: 8.2.0 , < unspecified (custom)
    Affected: unspecified , < 8.2.4 (custom)
    Create a notification for this product.
    Atlassian Bitbucket Server Affected: unspecified , < 7.6.16 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.8 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.19.5 (custom)
    Affected: 7.20.0 , < unspecified (custom)
    Affected: unspecified , < 7.20.2 (custom)
    Affected: 7.21.0 , < unspecified (custom)
    Affected: unspecified , < 7.21.2 (custom)
    Affected: 8.0.0
    Affected: 8.1.0
    Create a notification for this product.
    Atlassian Bitbucket Data Center Affected: unspecified , < 7.6.16 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.8 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.19.5 (custom)
    Affected: 7.20.0 , < unspecified (custom)
    Affected: unspecified , < 7.20.2 (custom)
    Affected: 7.21.0 , < unspecified (custom)
    Affected: unspecified , < 7.21.2 (custom)
    Affected: 8.0.0
    Affected: 8.1.0
    Create a notification for this product.
    Atlassian Confluence Server Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0
    Create a notification for this product.
    Atlassian Confluence Data Center Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0
    Create a notification for this product.
    Atlassian Crowd Server Affected: unspecified , < 4.3.8 (custom)
    Affected: 4.4.0 , < unspecified (custom)
    Affected: unspecified , < 4.4.2 (custom)
    Affected: 5.0.0
    Create a notification for this product.
    Atlassian Crowd Data Center Affected: unspecified , < 4.3.8 (custom)
    Affected: 4.4.0 , < unspecified (custom)
    Affected: unspecified , < 4.4.2 (custom)
    Affected: 5.0.0
    Create a notification for this product.
    Atlassian Crucible Affected: unspecified , < 4.8.10 (custom)
    Create a notification for this product.
    Atlassian Fisheye Affected: unspecified , < 4.8.10 (custom)
    Create a notification for this product.
    Atlassian Jira Core Server Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Software Server Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Software Data Center Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Service Management Server Affected: unspecified , < 4.13.22 (custom)
    Affected: 4.14.0 , < unspecified (custom)
    Affected: unspecified , < 4.20.10 (custom)
    Affected: 4.21.0 , < unspecified (custom)
    Affected: unspecified , < 4.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Service Management Data Center Affected: unspecified , < 4.13.22 (custom)
    Affected: 4.14.0 , < unspecified (custom)
    Affected: unspecified , < 4.20.10 (custom)
    Affected: 4.21.0 , < unspecified (custom)
    Affected: unspecified , < 4.22.4 (custom)
    Create a notification for this product.
    atlassian bamboo Affected: 7.2.0 , < 7.2.10 (custom)
    Affected: 8.0.0 , < 8.0.9 (custom)
    Affected: 8.1.0 , < 8.1.8 (custom)
    Affected: 8.2.0 , < 8.2.4 (custom)
        cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 0 , < 7.6.16 (custom)
    Affected: 7.7.0 , < 7.17.8 (custom)
    Affected: 7.18.0 , < 7.19.5 (custom)
    Affected: 7.20.1 , < 7.20.2 (custom)
    Affected: 7.21.0 , < 7.21.2 (custom)
        cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 8.0.0
        cpe:2.3:a:atlassian:bitbucket:8.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 8.1.0
        cpe:2.3:a:atlassian:bitbucket:8.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 0 , < 7.4.17 (custom)
    Affected: 7.5.0 , < 7.13.7 (custom)
    Affected: 7.14.0 , < 7.14.3 (custom)
    Affected: 7.15.0 , < 7.15.2 (custom)
    Affected: 7.16.0 , < 7.16.4 (custom)
    Affected: 7.17.0 , < 7.17.4 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 7.18.0
        cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 0 , < 7.4.17 (custom)
    Affected: 7.5.0 , < 7.13.7 (custom)
    Affected: 7.14.0 , < 7.14.3 (custom)
    Affected: 7.15.0 , < 7.15.2 (custom)
    Affected: 7.16.0 , < 7.16.4 (custom)
    Affected: 7.17.0 , < 7.17.4 (custom)
        cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 7.18.0
        cpe:2.3:a:atlassian:confluence_server:7.18.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crowd Affected: 0 , < 4.3.8 (custom)
    Affected: 4.4.0 , < 4.4.2 (custom)
        cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crowd Affected: 5.0.0
        cpe:2.3:a:atlassian:crowd:5.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crucible Affected: 0 , < 4.8.10 (custom)
        cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian fisheye Affected: 0 , < 4.8.10 (custom)
        cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_data_center Affected: 8.13.0 , < 8.13.22 (custom)
    Affected: 8.14.0 , < 8.20.10 (custom)
    Affected: 8.21.0 , < 8.22.4 (custom)
        cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_server Affected: 8.13.0 , < 8.13.22 (custom)
    Affected: 8.14.0 , < 8.20.10 (custom)
    Affected: 8.21.0 , < 8.22.4 (custom)
        cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_service_desk Affected: 0 , < 4.13.22 (custom)
        cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:server:*:*:*
    Create a notification for this product.
    atlassian jira_service_desk Affected: 0 , < 4.13.22 (custom)
        cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:data_center:*:*:*
    Create a notification for this product.
    atlassian jira_service_management Affected: 4.14.0 , < 4.20.10 (custom)
    Affected: 4.21.0 , < 4.22.4 (custom)
        cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*
    Create a notification for this product.
    atlassian jira_service_management Affected: 4.14.0 , < 4.20.10 (custom)
    Affected: 4.21.0 , < 4.22.4 (custom)
        cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*
    Create a notification for this product.
    Date Public
    2022-07-20 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:56:37.614Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/BAM-21795"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/BSERV-13370"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5815"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/FE-7410"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CRUC-8541"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bamboo",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.2.10",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.0.9",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.1.8",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.2.4",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.6.16",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.8",
                    "status": "affected",
                    "version": "7.7.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.19.5",
                    "status": "affected",
                    "version": "7.18.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.20.2",
                    "status": "affected",
                    "version": "7.20.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.21.2",
                    "status": "affected",
                    "version": "7.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:8.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.0.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:8.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.1.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.4.17",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.13.7",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.14.3",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.15.2",
                    "status": "affected",
                    "version": "7.15.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.16.4",
                    "status": "affected",
                    "version": "7.16.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.4",
                    "status": "affected",
                    "version": "7.17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.18.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.4.17",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.13.7",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.14.3",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.15.2",
                    "status": "affected",
                    "version": "7.15.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.16.4",
                    "status": "affected",
                    "version": "7.16.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.4",
                    "status": "affected",
                    "version": "7.17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:7.18.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.18.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crowd",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.3.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.4.2",
                    "status": "affected",
                    "version": "4.4.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crowd:5.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crowd",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.0.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crucible",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.8.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fisheye",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.8.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.13.22",
                    "status": "affected",
                    "version": "8.13.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.20.10",
                    "status": "affected",
                    "version": "8.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.22.4",
                    "status": "affected",
                    "version": "8.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.13.22",
                    "status": "affected",
                    "version": "8.13.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.20.10",
                    "status": "affected",
                    "version": "8.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.22.4",
                    "status": "affected",
                    "version": "8.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:server:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_desk",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.13.22",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:data_center:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_desk",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.13.22",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_management",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.20.10",
                    "status": "affected",
                    "version": "4.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.22.4",
                    "status": "affected",
                    "version": "4.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_management",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.20.10",
                    "status": "affected",
                    "version": "4.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.22.4",
                    "status": "affected",
                    "version": "4.21.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-26137",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-03T16:48:52.174175Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-03T17:10:16.886Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Bamboo Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.0.9",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.1.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.2.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Bamboo Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.0.9",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.1.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.2.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Bitbucket Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.6.16",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.19.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.20.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.21.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "8.0.0"
                },
                {
                  "status": "affected",
                  "version": "8.1.0"
                }
              ]
            },
            {
              "product": "Bitbucket Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.6.16",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.19.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.20.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.21.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "8.0.0"
                },
                {
                  "status": "affected",
                  "version": "8.1.0"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.18.0"
                }
              ]
            },
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.18.0"
                }
              ]
            },
            {
              "product": "Crowd Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "5.0.0"
                }
              ]
            },
            {
              "product": "Crowd Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "5.0.0"
                }
              ]
            },
            {
              "product": "Crucible",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.8.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Fisheye",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.8.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Core Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Software Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Software Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Service Management Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Service Management Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-07-20T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim\u2019s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-180",
                  "description": "Incorrect Behavior Order: Validate Before Canonicalize (CWE-180)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-20T17:25:23.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/BAM-21795"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/BSERV-13370"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5815"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/FE-7410"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CRUC-8541"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2022-07-20T00:00:00",
              "ID": "CVE-2022-26137",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Bamboo Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.0.9"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.1.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.2.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.2.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bamboo Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.0.9"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.1.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.2.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.2.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bitbucket Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.16"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.19.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.20.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.20.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.21.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.0.0"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bitbucket Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.16"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.19.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.20.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.20.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.21.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.0.0"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "7.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "7.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crowd Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.3.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.4.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.4.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crowd Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.3.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.4.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.4.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crucible",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.8.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Fisheye",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.8.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Core Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Software Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Software Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Service Management Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Service Management Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.22.4"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim\u2019s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Incorrect Behavior Order: Validate Before Canonicalize (CWE-180)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/BAM-21795",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/BAM-21795"
                },
                {
                  "name": "https://jira.atlassian.com/browse/BSERV-13370",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/BSERV-13370"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CONFSERVER-79476",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5815",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5815"
                },
                {
                  "name": "https://jira.atlassian.com/browse/FE-7410",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/FE-7410"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CRUC-8541",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CRUC-8541"
                },
                {
                  "name": "https://jira.atlassian.com/browse/JRASERVER-73897",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
                },
                {
                  "name": "https://jira.atlassian.com/browse/JSDSERVER-11863",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2022-26137",
        "datePublished": "2022-07-20T17:25:23.603Z",
        "dateReserved": "2022-02-25T00:00:00.000Z",
        "dateUpdated": "2024-10-03T17:10:16.886Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-26136 (GCVE-0-2022-26136)

    Vulnerability from cvelistv5 – Published: 2022-07-20 17:25 – Updated: 2024-10-03 16:43
    VLAI
    Summary
    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-03 15:26 UTC
    CWE
    • CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize (CWE-180).
    Impacted products
    Vendor Product Version
    Atlassian Bamboo Server Affected: unspecified , < 8.0.9 (custom)
    Affected: 8.1.0 , < unspecified (custom)
    Affected: unspecified , < 8.1.8 (custom)
    Affected: 8.2.0 , < unspecified (custom)
    Affected: unspecified , < 8.2.4 (custom)
    Create a notification for this product.
    Atlassian Bamboo Data Center Affected: unspecified , < 8.0.9 (custom)
    Affected: 8.1.0 , < unspecified (custom)
    Affected: unspecified , < 8.1.8 (custom)
    Affected: 8.2.0 , < unspecified (custom)
    Affected: unspecified , < 8.2.4 (custom)
    Create a notification for this product.
    Atlassian Bitbucket Server Affected: unspecified , < 7.6.16 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.8 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.19.5 (custom)
    Affected: 7.20.0 , < unspecified (custom)
    Affected: unspecified , < 7.20.2 (custom)
    Affected: 7.21.0 , < unspecified (custom)
    Affected: unspecified , < 7.21.2 (custom)
    Affected: 8.0.0
    Affected: 8.1.0
    Create a notification for this product.
    Atlassian Bitbucket Data Center Affected: unspecified , < 7.6.16 (custom)
    Affected: 7.7.0 , < unspecified (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.8 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.19.5 (custom)
    Affected: 7.20.0 , < unspecified (custom)
    Affected: unspecified , < 7.20.2 (custom)
    Affected: 7.21.0 , < unspecified (custom)
    Affected: unspecified , < 7.21.2 (custom)
    Affected: 8.0.0
    Affected: 8.1.0
    Create a notification for this product.
    Atlassian Confluence Server Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0
    Create a notification for this product.
    Atlassian Confluence Data Center Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0
    Create a notification for this product.
    Atlassian Crowd Server Affected: unspecified , < 4.3.8 (custom)
    Affected: 4.4.0 , < unspecified (custom)
    Affected: unspecified , < 4.4.2 (custom)
    Affected: 5.0.0
    Create a notification for this product.
    Atlassian Crowd Data Center Affected: unspecified , < 4.3.8 (custom)
    Affected: 4.4.0 , < unspecified (custom)
    Affected: unspecified , < 4.4.2 (custom)
    Affected: 5.0.0
    Create a notification for this product.
    Atlassian Crucible Affected: unspecified , < 4.8.10 (custom)
    Create a notification for this product.
    Atlassian Fisheye Affected: unspecified , < 4.8.10 (custom)
    Create a notification for this product.
    Atlassian Jira Core Server Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Software Server Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Software Data Center Affected: unspecified , < 8.13.22 (custom)
    Affected: 8.14.0 , < unspecified (custom)
    Affected: unspecified , < 8.20.10 (custom)
    Affected: 8.21.0 , < unspecified (custom)
    Affected: unspecified , < 8.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Service Management Server Affected: unspecified , < 4.13.22 (custom)
    Affected: 4.14.0 , < unspecified (custom)
    Affected: unspecified , < 4.20.10 (custom)
    Affected: 4.21.0 , < unspecified (custom)
    Affected: unspecified , < 4.22.4 (custom)
    Create a notification for this product.
    Atlassian Jira Service Management Data Center Affected: unspecified , < 4.13.22 (custom)
    Affected: 4.14.0 , < unspecified (custom)
    Affected: unspecified , < 4.20.10 (custom)
    Affected: 4.21.0 , < unspecified (custom)
    Affected: unspecified , < 4.22.4 (custom)
    Create a notification for this product.
    atlassian bamboo Affected: 7.2.0 , < 7.2.10 (custom)
    Affected: 8.0.0 , < 8.0.9 (custom)
    Affected: 8.1.0 , < 8.1.8 (custom)
    Affected: 8.2.0 , < 8.2.4 (custom)
        cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 0 , < 7.6.16 (custom)
    Affected: 7.7.0 , < 7.17.8 (custom)
    Affected: 7.18.0 , < 7.19.5 (custom)
    Affected: 7.20.0 , < 7.20.2 (custom)
    Affected: 7.21.0 , < 7.21.2 (custom)
        cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian bitbucket Affected: 8.0.0
    Affected: 8.1.0
        cpe:2.3:a:atlassian:bitbucket:8.0.0:*:*:*:*:*:*:*
        cpe:2.3:a:atlassian:bitbucket:8.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 0 , < 7.4.17 (custom)
    Affected: 7.5.0 , < 7.13.7 (custom)
    Affected: 7.14.0 , < 7.14.3 (custom)
    Affected: 7.15.0 , < 7.15.2 (custom)
    Affected: 7.16.0 , < 7.16.4 (custom)
    Affected: 7.17.0 , < 7.17.4 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_data_center Affected: 7.18.0
        cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 0 , < 7.4.17 (custom)
    Affected: 7.5.0 , < 7.13.7 (custom)
    Affected: 7.14.0 , < 7.14.3 (custom)
    Affected: 7.15.0 , < 7.15.2 (custom)
    Affected: 7.16.0 , < 7.16.4 (custom)
    Affected: 7.17.0 , < 7.17.4 (custom)
        cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 7.18.0
        cpe:2.3:a:atlassian:confluence_server:7.18.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crowd Affected: 0 , < 4.3.8 (custom)
    Affected: 4.4.0 , < 4.4.2 (custom)
        cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crowd Affected: 5.0.0
        cpe:2.3:a:atlassian:crowd:5.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian crucible Affected: 0 , < 4.8.10 (custom)
        cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian fisheye Affected: 0 , < 4.8.10 (custom)
        cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_data_center Affected: 8.13.0 , < 8.13.22 (custom)
    Affected: 8.14.0 , < 8.20.10 (custom)
    Affected: 8.21.0 , < 8.22.4 (custom)
        cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_server Affected: 8.13.0 , < 8.13.22 (custom)
    Affected: 8.14.0 , < 8.20.10 (custom)
    Affected: 8.21.0 , < 8.22.4 (custom)
        cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian jira_service_desk Affected: 0 , < 4.13.22 (custom)
        cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:server:*:*:*
    Create a notification for this product.
    atlassian jira_service_desk Affected: 0 , < 4.13.22 (custom)
        cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:data_center:*:*:*
    Create a notification for this product.
    atlassian jira_service_management Affected: 4.14.0 , < 4.20.10 (custom)
    Affected: 4.21.0 , < 4.22.4 (custom)
        cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*
    Create a notification for this product.
    atlassian jira_service_management Affected: 4.14.0 , < 4.20.10 (custom)
    Affected: 4.21.0 , < 4.22.4 (custom)
        cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*
    Create a notification for this product.
    Date Public
    2022-07-20 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:56:37.592Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/BAM-21795"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/BSERV-13370"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CWD-5815"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/FE-7410"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CRUC-8541"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bamboo:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bamboo",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.2.10",
                    "status": "affected",
                    "version": "7.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.0.9",
                    "status": "affected",
                    "version": "8.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.1.8",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.2.4",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.6.16",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.8",
                    "status": "affected",
                    "version": "7.7.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.19.5",
                    "status": "affected",
                    "version": "7.18.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.20.2",
                    "status": "affected",
                    "version": "7.20.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.21.2",
                    "status": "affected",
                    "version": "7.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:bitbucket:8.0.0:*:*:*:*:*:*:*",
                  "cpe:2.3:a:atlassian:bitbucket:8.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bitbucket",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.0.0"
                  },
                  {
                    "status": "affected",
                    "version": "8.1.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.4.17",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.13.7",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.14.3",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.15.2",
                    "status": "affected",
                    "version": "7.15.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.16.4",
                    "status": "affected",
                    "version": "7.16.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.4",
                    "status": "affected",
                    "version": "7.17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:7.18.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.18.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "7.4.17",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.13.7",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.14.3",
                    "status": "affected",
                    "version": "7.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.15.2",
                    "status": "affected",
                    "version": "7.15.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.16.4",
                    "status": "affected",
                    "version": "7.16.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.17.4",
                    "status": "affected",
                    "version": "7.17.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:7.18.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.18.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crowd:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crowd",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.3.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.4.2",
                    "status": "affected",
                    "version": "4.4.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crowd:5.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crowd",
                "vendor": "atlassian",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.0.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:crucible:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "crucible",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.8.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:fisheye:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fisheye",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.8.10",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.13.22",
                    "status": "affected",
                    "version": "8.13.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.20.10",
                    "status": "affected",
                    "version": "8.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.22.4",
                    "status": "affected",
                    "version": "8.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "8.13.22",
                    "status": "affected",
                    "version": "8.13.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.20.10",
                    "status": "affected",
                    "version": "8.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "8.22.4",
                    "status": "affected",
                    "version": "8.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:server:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_desk",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.13.22",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_desk:-:*:*:*:data_center:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_desk",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.13.22",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_management",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.20.10",
                    "status": "affected",
                    "version": "4.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.22.4",
                    "status": "affected",
                    "version": "4.21.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "jira_service_management",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "4.20.10",
                    "status": "affected",
                    "version": "4.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.22.4",
                    "status": "affected",
                    "version": "4.21.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-26136",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-03T15:26:49.090400Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-03T16:43:16.268Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Bamboo Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.0.9",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.1.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.2.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Bamboo Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.0.9",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.1.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.2.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Bitbucket Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.6.16",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.19.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.20.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.21.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "8.0.0"
                },
                {
                  "status": "affected",
                  "version": "8.1.0"
                }
              ]
            },
            {
              "product": "Bitbucket Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.6.16",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.7.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.19.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.20.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.20.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.21.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "8.0.0"
                },
                {
                  "status": "affected",
                  "version": "8.1.0"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.18.0"
                }
              ]
            },
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "7.18.0"
                }
              ]
            },
            {
              "product": "Crowd Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "5.0.0"
                }
              ]
            },
            {
              "product": "Crowd Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "5.0.0"
                }
              ]
            },
            {
              "product": "Crucible",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.8.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Fisheye",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.8.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Core Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Software Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Software Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "8.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "8.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "8.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Service Management Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Jira Service Management Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "4.13.22",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.20.10",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "4.21.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.22.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-07-20T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-180",
                  "description": "Incorrect Behavior Order: Validate Before Canonicalize (CWE-180).",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-07-20T17:25:18.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/BAM-21795"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/BSERV-13370"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CWD-5815"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/FE-7410"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CRUC-8541"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2022-07-20T00:00:00",
              "ID": "CVE-2022-26136",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Bamboo Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.0.9"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.1.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.2.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.2.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bamboo Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.0.9"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.1.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.1.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.2.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.2.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bitbucket Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.16"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.19.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.20.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.20.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.21.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.0.0"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Bitbucket Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.6.16"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.7.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.19.5"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.20.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.20.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.21.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.0.0"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "8.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "7.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "7.18.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crowd Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.3.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.4.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.4.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crowd Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.3.8"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.4.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.4.2"
                              },
                              {
                                "version_affected": "=",
                                "version_value": "5.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Crucible",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.8.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Fisheye",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.8.10"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Core Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Software Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Software Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "8.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "8.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Service Management Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.22.4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Jira Service Management Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.13.22"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.20.10"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "4.21.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "4.22.4"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Incorrect Behavior Order: Validate Before Canonicalize (CWE-180)."
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/BAM-21795",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/BAM-21795"
                },
                {
                  "name": "https://jira.atlassian.com/browse/BSERV-13370",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/BSERV-13370"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CONFSERVER-79476",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CONFSERVER-79476"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CWD-5815",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CWD-5815"
                },
                {
                  "name": "https://jira.atlassian.com/browse/FE-7410",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/FE-7410"
                },
                {
                  "name": "https://jira.atlassian.com/browse/CRUC-8541",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CRUC-8541"
                },
                {
                  "name": "https://jira.atlassian.com/browse/JRASERVER-73897",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/JRASERVER-73897"
                },
                {
                  "name": "https://jira.atlassian.com/browse/JSDSERVER-11863",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/JSDSERVER-11863"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2022-26136",
        "datePublished": "2022-07-20T17:25:18.803Z",
        "dateReserved": "2022-02-25T00:00:00.000Z",
        "dateUpdated": "2024-10-03T16:43:16.268Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-26134 (GCVE-0-2022-26134)

    Vulnerability from cvelistv5 – Published: 2022-06-03 21:51 – Updated: 2025-10-21 23:15
    VLAI
    Summary
    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-04 14:18 UTC
    CWE
    • Remote Code Execution
    • CWE-917 - Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
    Impacted products
    Vendor Product Version
    Atlassian Confluence Data Center Affected: next of 1.3.0 , < unspecified (custom)
    Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.13.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.18.1 (custom)
    Create a notification for this product.
    Atlassian Confluence Server Affected: next of 1.3.0 , < unspecified (custom)
    Affected: unspecified , < 7.4.17 (custom)
    Affected: 7.13.0 , < unspecified (custom)
    Affected: unspecified , < 7.13.7 (custom)
    Affected: 7.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.14.3 (custom)
    Affected: 7.15.0 , < unspecified (custom)
    Affected: unspecified , < 7.15.2 (custom)
    Affected: 7.16.0 , < unspecified (custom)
    Affected: unspecified , < 7.16.4 (custom)
    Affected: 7.17.0 , < unspecified (custom)
    Affected: unspecified , < 7.17.4 (custom)
    Affected: 7.18.0 , < unspecified (custom)
    Affected: unspecified , < 7.18.1 (custom)
    Create a notification for this product.
    Date Public
    2022-05-31 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T04:56:37.787Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-79016"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/167432/Confluence-OGNL-Injection-Proof-Of-Concept.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/167431/Through-The-Wire-CVE-2022-26134-Confluence-Proof-Of-Concept.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-26134",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-04T14:18:48.606174Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2022-06-02",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26134"
                  },
                  "type": "kev"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-917",
                    "description": "CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement (\u0027Expression Language Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:15:38.769Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26134"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2022-06-02T00:00:00.000Z",
                "value": "CVE-2022-26134 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "next of 1.3.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.13.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.18.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "next of 1.3.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.4.17",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.13.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.13.7",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.14.3",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.15.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.15.2",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.16.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.16.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.17.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.17.4",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.18.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.18.1",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-05-31T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Remote Code Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-06-30T05:20:13.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CONFSERVER-79016"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://packetstormsecurity.com/files/167432/Confluence-OGNL-Injection-Proof-Of-Concept.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://packetstormsecurity.com/files/167431/Through-The-Wire-CVE-2022-26134-Confluence-Proof-Of-Concept.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2022-05-31T20:00:00",
              "ID": "CVE-2022-26134",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Confluence Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003e",
                                "version_value": "1.3.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.13.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.18.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003e",
                                "version_value": "1.3.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.17"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.13.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.13.7"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.14.3"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.15.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.15.2"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.16.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.16.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.17.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.17.4"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.18.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.18.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Remote Code Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CONFSERVER-79016",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CONFSERVER-79016"
                },
                {
                  "name": "http://packetstormsecurity.com/files/167432/Confluence-OGNL-Injection-Proof-Of-Concept.html",
                  "refsource": "MISC",
                  "url": "http://packetstormsecurity.com/files/167432/Confluence-OGNL-Injection-Proof-Of-Concept.html"
                },
                {
                  "name": "http://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html",
                  "refsource": "MISC",
                  "url": "http://packetstormsecurity.com/files/167430/Confluence-OGNL-Injection-Remote-Code-Execution.html"
                },
                {
                  "name": "http://packetstormsecurity.com/files/167431/Through-The-Wire-CVE-2022-26134-Confluence-Proof-Of-Concept.html",
                  "refsource": "MISC",
                  "url": "http://packetstormsecurity.com/files/167431/Through-The-Wire-CVE-2022-26134-Confluence-Proof-Of-Concept.html"
                },
                {
                  "name": "http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html",
                  "refsource": "MISC",
                  "url": "http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html"
                },
                {
                  "name": "https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html",
                  "refsource": "MISC",
                  "url": "https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2022-26134",
        "datePublished": "2022-06-03T21:51:57.134Z",
        "dateReserved": "2022-02-25T00:00:00.000Z",
        "dateUpdated": "2025-10-21T23:15:38.769Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-39114 (GCVE-0-2021-39114)

    Vulnerability from cvelistv5 – Published: 2022-04-05 04:00 – Updated: 2024-10-04 19:06
    VLAI
    Summary
    Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-04 18:55 UTC
    CWE
    • Remote Code Execution
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    References
    Impacted products
    Vendor Product Version
    Atlassian Confluence Server Affected: unspecified , < 6.13.23 (custom)
    Affected: 6.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.4.11 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.11.6 (custom)
    Affected: 7.12.0 , < unspecified (custom)
    Affected: unspecified , < 7.12.5 (custom)
    Create a notification for this product.
    Atlassian Confluence Data Center Affected: unspecified , < 6.13.23 (custom)
    Affected: 6.14.0 , < unspecified (custom)
    Affected: unspecified , < 7.4.11 (custom)
    Affected: 7.5.0 , < unspecified (custom)
    Affected: unspecified , < 7.11.6 (custom)
    Affected: 7.12.0 , < unspecified (custom)
    Affected: unspecified , < 7.12.5 (custom)
    Create a notification for this product.
    atlassian confluence_data_center Affected: 0 , < 6.13.23 (custom)
    Affected: 6.14.0 , < 7.4.11 (custom)
    Affected: 7.5.0 , < 7.11.6 (custom)
    Affected: 7.12.0 , < 7.12.5 (custom)
        cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
    Create a notification for this product.
    atlassian confluence_server Affected: 0 , < 6.13.23 (custom)
    Affected: 6.14.0 , < 7.4.11 (custom)
    Affected: 7.5.0 , < 7.11.6 (custom)
    Affected: 7.12.0 , < 7.12.5 (custom)
        cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2022-02-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T01:58:17.751Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.atlassian.com/browse/CONFSERVER-68844"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_data_center",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "6.13.23",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.4.11",
                    "status": "affected",
                    "version": "6.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.11.6",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.12.5",
                    "status": "affected",
                    "version": "7.12.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "confluence_server",
                "vendor": "atlassian",
                "versions": [
                  {
                    "lessThan": "6.13.23",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.4.11",
                    "status": "affected",
                    "version": "6.14.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.11.6",
                    "status": "affected",
                    "version": "7.5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "7.12.5",
                    "status": "affected",
                    "version": "7.12.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2021-39114",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-04T18:55:58.863918Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-04T19:06:17.769Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Confluence Server",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "6.13.23",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "6.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.4.11",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.11.6",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.12.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.12.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Confluence Data Center",
              "vendor": "Atlassian",
              "versions": [
                {
                  "lessThan": "6.13.23",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "6.14.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.4.11",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.5.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.11.6",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                },
                {
                  "lessThan": "unspecified",
                  "status": "affected",
                  "version": "7.12.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "7.12.5",
                  "status": "affected",
                  "version": "unspecified",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-02-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Remote Code Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-04-05T04:00:18.000Z",
            "orgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
            "shortName": "atlassian"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.atlassian.com/browse/CONFSERVER-68844"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@atlassian.com",
              "DATE_PUBLIC": "2022-02-09T00:00:00",
              "ID": "CVE-2021-39114",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Confluence Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "6.13.23"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "6.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.11"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.11.6"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.12.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.12.5"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Confluence Data Center",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_value": "6.13.23"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "6.14.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.4.11"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.5.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.11.6"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_value": "7.12.0"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_value": "7.12.5"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Atlassian"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Remote Code Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.atlassian.com/browse/CONFSERVER-68844",
                  "refsource": "MISC",
                  "url": "https://jira.atlassian.com/browse/CONFSERVER-68844"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f08a6ab8-ed46-4c22-8884-d911ccfe3c66",
        "assignerShortName": "atlassian",
        "cveId": "CVE-2021-39114",
        "datePublished": "2022-04-05T04:00:18.966Z",
        "dateReserved": "2021-08-16T00:00:00.000Z",
        "dateUpdated": "2024-10-04T19:06:17.769Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }