CISA Known Exploited Vulnerability

CVE-2021-26084 Ransomware

Atlassian · Confluence Server and Data Center

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-917
Ransomware Known

CISA description

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

Required action

Apply updates per vendor instructions.