#VU47860 Path traversal in Confluence Server - CVE-2019-3396
Published: March 25, 2019 / Updated: September 19, 2025
Confluence Server
Atlassian
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the Widget Connector macro. A remote attacker can perform a server-side template injection and read arbitrary files on the system, leading to remote code execution.