First published: Thu Apr 01 2021(Updated: )
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Confluence Data Center | <5.8.6 | |
Atlassian Confluence Server | <5.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26072 is a security vulnerability in Confluence Server and Confluence Data Center before version 5.8.6 that allows remote attackers to manipulate the content of internal network resources via a blind SSRF vulnerability.
CVE-2021-26072 could allow remote attackers to manipulate the content of internal network resources in Confluence Server and Confluence Data Center before version 5.8.6.
CVE-2021-26072 has a severity rating of 4.3 (medium).
To fix CVE-2021-26072, upgrade Confluence Server and Confluence Data Center to version 5.8.6 or later.
You can find more information about CVE-2021-26072 in the Atlassian Jira issue CONFSERVER-61399.