Atlassian

Confluence Server

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.46%
  • Veröffentlicht 26.07.2022 04:15:11
  • Zuletzt bearbeitet 21.11.2024 05:29:13

The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or Ja...

  • EPSS 0.07%
  • Veröffentlicht 20.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security...

  • EPSS 0.28%
  • Veröffentlicht 20.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:30

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulner...

Warnung Exploit
  • EPSS 94.41%
  • Veröffentlicht 03.06.2022 22:15:07
  • Zuletzt bearbeitet 24.10.2025 13:38:30

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1....

  • EPSS 0.36%
  • Veröffentlicht 05.04.2022 04:15:08
  • Zuletzt bearbeitet 21.11.2024 06:18:36

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions...

  • EPSS 0.16%
  • Veröffentlicht 15.02.2022 04:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:02

Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects ins...

Warnung Exploit
  • EPSS 94.44%
  • Veröffentlicht 30.08.2021 07:15:06
  • Zuletzt bearbeitet 24.10.2025 13:38:44

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before ...

Warnung Exploit
  • EPSS 94.21%
  • Veröffentlicht 03.08.2021 00:15:08
  • Zuletzt bearbeitet 24.10.2025 13:38:39

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5....

  • EPSS 0.1%
  • Veröffentlicht 07.05.2021 06:15:09
  • Zuletzt bearbeitet 12.02.2025 21:15:10

Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.

  • EPSS 0.23%
  • Veröffentlicht 07.05.2021 06:15:09
  • Zuletzt bearbeitet 12.02.2025 21:15:09

Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.