CISA Known Exploited Vulnerability

CVE-2021-26085 Ransomware

Atlassian · Confluence Server

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Date added
BOD 22-01 due date
CWE CWE-425
Ransomware Known

CISA description

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

Required action

Apply updates per vendor instructions.