Vulnerabilities > Atlassian > Confluence > 5.4.1

DATE CVE VULNERABILITY TITLE RISK
2020-07-01 CVE-2020-4027 Injection vulnerability in Atlassian Confluence
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros.
network
low complexity
atlassian CWE-74
6.5
2020-02-06 CVE-2019-20406 Uncontrolled Search Path Element vulnerability in Atlassian Confluence
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.
4.4
2019-11-08 CVE-2019-15005 Missing Authorization vulnerability in Atlassian products
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check.
network
low complexity
atlassian CWE-862
4.0
2019-04-18 CVE-2019-3398 Path Traversal vulnerability in Atlassian Confluence
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.
network
low complexity
atlassian CWE-22
critical
9.0
2019-03-25 CVE-2019-3396 Path Traversal vulnerability in Atlassian Confluence
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
network
low complexity
atlassian CWE-22
critical
10.0
2019-03-25 CVE-2019-3395 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Confluence and Confluence Server
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery.
network
low complexity
atlassian CWE-918
7.5
2018-07-10 CVE-2018-13389 Improper Input Validation vulnerability in Atlassian Confluence
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.
network
atlassian CWE-20
4.3
2018-02-02 CVE-2017-18086 Cross-site Scripting vulnerability in Atlassian Confluence
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.
network
atlassian CWE-79
4.3
2018-02-02 CVE-2017-18085 Cross-site Scripting vulnerability in Atlassian Confluence
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
network
atlassian CWE-79
4.3
2018-02-02 CVE-2017-18084 Cross-site Scripting vulnerability in Atlassian Confluence
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.
network
atlassian CWE-79
3.5