CVE-2024-21673

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 16, 2024
Updated: Jan 22, 2024
CWE ID 94

Summary

CVE-2024-21673 is a high severity Remote Code Execution (RCE) vulnerability affecting versions 7.13.0 of Confluence Data Center and Server. With a CVSS Score of 8.0, this issue allows authenticated attackers to execute arbitrary code and potentially expose assets in the environment, posing a significant risk to confidentiality, integrity, and availability. The vulnerability does not require user interaction. To mitigate the risk, Atlassian advises Confluence Data Center and Server customers to upgrade to the latest version. If upgrading is not an option, customers are recommended to upgrade to supported fixed versions, such as Confluence Data Center and Server 7.19.18, 8.5.5, or 8.7.2. The release notes and latest version downloads can be found on the Atlassian website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Confluence Server
  • Confluence Data Center

Affected Vendors

  • Atlassian Corporation Pty Ltd.