Vulnerabilities > Atlassian > Confluence Data Center > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-18 CVE-2023-22508 Unspecified vulnerability in Atlassian Confluence Data Center and Confluence Server
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server.
network
low complexity
atlassian
8.8
2023-07-18 CVE-2023-22505 Unspecified vulnerability in Atlassian Confluence Data Center and Confluence Server
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that you upgrade your instance to latest version.
network
low complexity
atlassian
8.8
2022-11-15 CVE-2022-42977 Path Traversal vulnerability in Atlassian Confluence Data Center
The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it.
network
low complexity
atlassian CWE-22
7.5
2022-11-15 CVE-2022-42978 Incorrect Authorization vulnerability in Atlassian Confluence Data Center
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled.
network
low complexity
atlassian CWE-863
7.5
2022-07-20 CVE-2022-26137 Origin Validation Error vulnerability in Atlassian products
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses.
network
low complexity
atlassian CWE-346
8.8
2022-04-05 CVE-2021-39114 Code Injection vulnerability in Atlassian Confluence Data Center and Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload.
network
low complexity
atlassian CWE-94
8.8
2022-02-15 CVE-2021-43940 Uncontrolled Search Path Element vulnerability in Atlassian Confluence Data Center
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer.
local
low complexity
atlassian CWE-427
7.8