CVE-2021-26072: SSRF
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-26072?
CVE-2021-26072 is a security vulnerability in Confluence Server and Confluence Data Center before version 5.8.6 that allows remote attackers to manipulate the content of internal network resources via a blind SSRF vulnerability.
How does CVE-2021-26072 impact Confluence?
CVE-2021-26072 could allow remote attackers to manipulate the content of internal network resources in Confluence Server and Confluence Data Center before version 5.8.6.
What is the severity of CVE-2021-26072?
CVE-2021-26072 has a severity rating of 4.3 (medium).
How can I fix CVE-2021-26072?
To fix CVE-2021-26072, upgrade Confluence Server and Confluence Data Center to version 5.8.6 or later.
Where can I find more information about CVE-2021-26072?
You can find more information about CVE-2021-26072 in the Atlassian Jira issue CONFSERVER-61399.