Skip to content
COOEY

EXPOSURES › CVE-2019-3396

CVE-2019-3396

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-3396 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 95/100 ransomwarerceexploited-in-wild

Atlassian Confluence Server and Data Center had a server-side template injection vulnerability actively exploited by ransomware actors, enabling remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Significant negative impact due to active exploitation and inclusion in KEV lists.
cvefeed.io ↗ severe-fallout -0.90
Strongly negative due to KEV listing indicating active exploitation.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is one of the highest-signal inputs for risk-based patch mana"
cybersecuritynews.com ↗ severe-fallout -0.80
Negative, highlights active exploitation and potential for severe consequences.
"Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems."
cooey ↗ severe-fallout -0.60
Neutral reporting of the vulnerability.
"Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution."
cvedb.shodan.io ↗ severe-fallout -0.50
Neutral, lists the vulnerability in a database.
www.cvefind.com ↗ severe-fallout -0.40
Neutral, simply lists the vulnerability in a database.
app.opencve.io ↗ severe-fallout -0.30
Neutral, describes the vulnerability in a list of CVEs.
xposedornot.com ↗ severe-fallout +0.00
Neutral, simply lists the vulnerability in a breach directory.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.