Skip to content
COOEY

EXPOSURES › CVE-2019-3398

CVE-2019-3398

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-3398 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

A path traversal flaw in Atlassian Confluence Server and Data Center allowed privileged remote attackers to write files and execute code.

This path traversal vulnerability in Confluence Server and Data Center enabled remote code execution for privileged attackers, directly impacting DIB organizations relying on the platform for collaboration and document management. The flaw was actively exploited in the wild, highlighting the severe risks of unpatched software and the critical need for rigorous patch management and continuous vulnerability monitoring to prevent similar compromises.

Shame score — The vulnerability was actively exploited in the wild, demonstrating a severe failure in patch management and security hygiene that directly endangered DIB systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.60
Acknowledged vulnerability, but no explicit condemnation.
cooey ↗ negative -0.60
Technical description, no judgment.
"Atlassian Confluence Server and Data Center contain a path traversal vulnerability."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.