CVE-2019-3396: Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
Other sources
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Confluence Server and Data Center (Widget Connector macro)to a version that resolves this vulnerability.Fixed in 6.6.12 - Upgrade
Upgrade
Atlassian Confluence Server and Data Center (Widget Connector macro)to a version that resolves this vulnerability.Fixed in 6.12.3 - Upgrade
Upgrade
Atlassian Confluence Server and Data Center (Widget Connector macro)to a version that resolves this vulnerability.Fixed in 6.13.3 - Upgrade
Upgrade
Atlassian Confluence Server and Data Center (Widget Connector macro)to a version that resolves this vulnerability.Fixed in 6.14.2
Event History
Frequently Asked Questions
What is CVE-2019-3396?
CVE-2019-3396 is a vulnerability in Atlassian Confluence Server and Data Center that allows server-side template injection.
How severe is CVE-2019-3396?
CVE-2019-3396 has a severity rating of 9.8, which is considered critical.
Which versions of Atlassian Confluence are affected by CVE-2019-3396?
Versions up to and including 6.6.12, between 6.7.0 and 6.12.3, between 6.13.0 and 6.13.3, and between 6.14.0 and 6.14.2 of Atlassian Confluence Server and Data Center are affected.
How can I fix CVE-2019-3396?
To fix CVE-2019-3396, you should upgrade Atlassian Confluence Server and Data Center to version 6.6.12 or higher, 6.12.3 or higher, 6.13.3 or higher, or 6.14.2 or higher.
Where can I find more information about CVE-2019-3396?
You can find more information about CVE-2019-3396 at the following references: [http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.html](http://packetstormsecurity.com/files/152568/Atlassian-Confluence-Widget-Connector-Macro-Velocity-Template-Injection.html), [http://packetstormsecurity.com/files/161065/Atlassian-Confluence-6.12.1-Template-Injection.html](http://packetstormsecurity.com/files/161065/Atlassian-Confluence-6.12.1-Template-Injection.html), and [http://www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connector](http://www.rapid7.com/db/modules/exploit/multi/http/confluence_widget_connector).