CVE-2024-21673: Code Injection
This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server.
Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and does not require user interaction.
Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release
See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Confluence Data Center and Serverto a version that resolves this vulnerability.Fixed in 7.19.18 - Upgrade
Upgrade
Confluence Data Center and Serverto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
Confluence Data Center and Serverto a version that resolves this vulnerability.Fixed in 8.7.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21673?
CVE-2024-21673 has a high severity rating with a CVSS score of 8.0.
How do I fix CVE-2024-21673?
To fix CVE-2024-21673, update your Confluence Data Center or Server to versions 7.19.19, 8.5.6, or 8.7.3 or later.
What types of attacks can CVE-2024-21673 facilitate?
CVE-2024-21673 allows for Remote Code Execution (RCE), enabling authenticated attackers to execute arbitrary code.
Which versions of Confluence are affected by CVE-2024-21673?
CVE-2024-21673 affects Confluence Data Center and Server versions from 7.13.0 through 8.7.2.
Is authentication required to exploit CVE-2024-21673?
Yes, an attacker must be authenticated to exploit CVE-2024-21673.