RCE Vulnerability in Atlassian Confluence Data Center and Confluence Server
Proof-of-concept exploit code released for RCE vulnerability CVE-2024-21683
Summary
Proof-of-concept exploit code released for RCE vulnerability CVE-2024-21683
Affected platforms
The following platforms are known to be affected:
Threat details
More vulnerabilities covered in Atlassian's May 2024 Security Bulletin
Other vulnerabilities affecting the Confluence product line, including the critical severity vulnerability known as CVE-2024-1597, are named in the May 2024 Security Bulletin. These vulnerabilities concern SQL injection, improper authorisation, and denial-of-service.
Other Atlassian products, such as Bamboo, Bitbucket, Crowd, Jira, and Jira Service, also have security updates available.
Introduction
Atlassian has released an advisory to address a remote code execution (RCE) vulnerability with a CVSSv3 score of 8.3, affecting Confluence Server and Confluence Data Center. A remote, authenticated attacker could exploit vulnerability CVE-2024-21683 to execute arbitrary code, resulting in a high impact to confidentiality, high impact to integrity, high impact to availability, and requiring no user interaction.
Proof-of-concept exploit code has been released for CVE-2024-21683.
Potential Exploitation of Confluence
Atlassian Confluence instances are often externally-facing by design and present an attractive target for exploitation by nation state and cyber criminal threat groups. Confluence vulnerabilities have been heavily targeted with exploits developed rapidly after vulnerability disclosure, leading to exploitation in the wild.
Proof-of-concept code has been released for CVE-2024-21683, so exploitation is considered more likely.
Remediation advice
Affected organisations are encouraged to review Atlassian's CVE-2024-21683 - RCE (Remote Code Execution) in Confluence Data Center and Server advisory and apply the relevant updates as soon as practicable.
Additional advisories for Confluence and other Atlassian product lines are in the May 2024 Security Bulletin.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 29 May 2024 3:20 pm