U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-21676

Change History

CVE Modified by Atlassian 4/18/2024 1:15:48 PM

Action Type Old Value New Value
Removed CVSS V3
Atlassian AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

								
						
Changed Description
This High severity Injection vulnerability was introduced in versions 7.3.0 of Confluence Data Center. 

This Injection vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.  

Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: 		 		

Confluence Data Center 8.5: Upgrade to a release greater than or equal to 8.5.8 

See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center from the download center (https://www.atlassian.com/software/confluence/download-archives). 

This vulnerability was discovered by l3yx and reported via our Bug Bounty program
Rejected reason: This CVE's publication may have been a false positive or a mistake. As a result, we have rejected this record.
Removed Reference
Atlassian https://jira.atlassian.com/rest/api/2/issue/2005000

								
						

CVE Rejected by Atlassian 4/18/2024 1:15:48 PM

Action Type Old Value New Value

CVE Translated by Atlassian 4/18/2024 1:15:48 PM

Action Type Old Value New Value
Removed Translation
Title: Confluence Data Center
Description: Esta vulnerabilidad de inyección de alta gravedad se introdujo en las versiones 7.3.0 de Confluence Data Center. Esta vulnerabilidad de inyección, con una puntuación CVSS de 8,8, permite a un atacante no autenticado modificar las acciones tomadas por una llamada al sistema, lo que tiene un alto impacto en la confidencialidad, un alto impacto en la integridad, un alto impacto en la disponibilidad y requiere la interacción del usuario. Atlassian recomienda que los clientes de Confluence Data Center actualicen a la última versión; si no pueden hacerlo, actualicen su instancia a una de las versiones fijas admitidas especificadas: Confluence Data Center 8.5: actualice a una versión mayor o igual a 8.5.8 Consulte las notas de la versión (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). Puede descargar la última versión de Confluence Data Center desde el centro de descargas (https://www.atlassian.com/software/confluence/download-archives). Esta vulnerabilidad fue descubierta por l3yx y reportada a través de nuestro programa Bug Bounty.