Lucene search

K
cvelistAtlassianCVELIST:CVE-2021-39114
HistoryFeb 09, 2022 - 12:00 a.m.

CVE-2021-39114

2022-02-0900:00:00
atlassian
www.cve.org

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.8%

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

CNA Affected

[
  {
    "product": "Confluence Server",
    "vendor": "Atlassian",
    "versions": [
      {
        "lessThan": "6.13.23",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "6.14.0",
        "versionType": "custom"
      },
      {
        "lessThan": "7.4.11",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "7.5.0",
        "versionType": "custom"
      },
      {
        "lessThan": "7.11.6",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "7.12.0",
        "versionType": "custom"
      },
      {
        "lessThan": "7.12.5",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Confluence Data Center",
    "vendor": "Atlassian",
    "versions": [
      {
        "lessThan": "6.13.23",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "6.14.0",
        "versionType": "custom"
      },
      {
        "lessThan": "7.4.11",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "7.5.0",
        "versionType": "custom"
      },
      {
        "lessThan": "7.11.6",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "7.12.0",
        "versionType": "custom"
      },
      {
        "lessThan": "7.12.5",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.8%

Related for CVELIST:CVE-2021-39114