CISA Known Exploited Vulnerability

CVE-2019-3398

Atlassian · Confluence Server and Data Center

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Date added
BOD 22-01 due date
CWE CWE-22
Ransomware Unknown

CISA description

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

Required action

Apply updates per vendor instructions.