CVE-2019-3396
Atlassian Confluence Server
Published 25 Mar 2019 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
References
- packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/161065/Atlassian-Confluence-6.12.1-Template-Injection.html · Exploit, Third Party Advisory, VDB Entry
- www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connector · Exploit, Third Party Advisory, VDB Entry
- jira.atlassian.com/browse/CONFSERVER-57974 · Issue Tracking, Patch, Vendor Advisory
- www.exploit-db.com/exploits/46731/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-3396 · US Government Resource