Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
References
Link Resource
https://jira.atlassian.com/browse/CONFSERVER-68844 Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: atlassian

Published: 2022-02-09T00:00:00

Updated: 2022-04-05T04:00:18

Reserved: 2021-08-16T00:00:00


Link: CVE-2021-39114

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-04-05T04:15:08.707

Modified: 2022-07-12T17:42:04.277


Link: CVE-2021-39114

JSON object: View

cve-icon Redhat Information

No data.

CWE