CVE-2021-26084

Description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.44

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-26084 are affected in Atlassian Confluence 6.9.3Windows
Vulnerabilities CVE-2021-26084,CVE-2021-43940 are affected in Atlassian Confluence 7.4.9Windows
Vulnerabilities CVE-2021-26084,CVE-2021-39114,CVE-2021-43940 are affected in Atlassian Confluence 7.9.3Windows
Vulnerabilities CVE-2021-26084 are affected in Atlassian Jira Core Data Center 7.12.3Windows
Vulnerabilities CVE-2021-26084 are affected in Atlassian Jira Core Data Center 7.9.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234