EXPOSURES › CVE-2019-3398
CVE-2019-3398
HIGH ⌖ ON CISA KEV · EXPLOITEDA path traversal flaw in Atlassian Confluence Server and Data Center allowed privileged remote attackers to write files and execute code.
This path traversal vulnerability in Confluence Server and Data Center enabled remote code execution for privileged attackers, directly impacting DIB organizations relying on the platform for collaboration and document management. The flaw was actively exploited in the wild, highlighting the severe risks of unpatched software and the critical need for rigorous patch management and continuous vulnerability monitoring to prevent similar compromises.
Shame score — The vulnerability was actively exploited in the wild, demonstrating a severe failure in patch management and security hygiene that directly endangered DIB systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.
"Atlassian Confluence Server and Data Center contain a path traversal vulnerability."