CVE-2024-21674: Code Injection
This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server.
Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, no impact to integrity, no impact to availability, and does not require user interaction.
Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Confluence Data Center and Server 7.19: Upgrade to a release 7.19.18, or any higher 7.19.x release Confluence Data Center and Server 8.5: Upgrade to a release 8.5.5 or any higher 8.5.x release Confluence Data Center and Server 8.7: Upgrade to a release 8.7.2 or any higher release
See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Confluence Data Center and Serverto a version that resolves this vulnerability.Fixed in 7.19.18 - Upgrade
Upgrade
Confluence Data Center and Serverto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
Confluence Data Center and Serverto a version that resolves this vulnerability.Fixed in 8.7.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21674?
CVE-2024-21674 has a high severity level with a CVSS Score of 8.6.
How do I fix CVE-2024-21674?
To address CVE-2024-21674, it is recommended to upgrade to a fixed version of Confluence Data Center or Server.
Which versions are affected by CVE-2024-21674?
CVE-2024-21674 affects Confluence Data Center versions between 7.13.0 and 8.7.2, as well as Confluence Server for the same version ranges.
What type of vulnerability is CVE-2024-21674?
CVE-2024-21674 is categorized as a Remote Code Execution (RCE) vulnerability.
Can an unauthenticated attacker exploit CVE-2024-21674?
Yes, CVE-2024-21674 can be exploited by an unauthenticated attacker.