Input validation error in Confluence Server and Confluence Data Center - CVE-2024-21683
Published: May 24, 2024 / Updated: December 6, 2024
Vulnerability identifier: #VU89803
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21683
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user can pass specially crafted input to the application and execute arbitrary code on the system.
Affected software
Confluence Server
Confluence Data Center
Confluence Data Center
How to mitigate CVE-2024-21683
Install updates from vendor's website.
Confluence Server - addressed in versions 7.19.22, 8.5.9, 8.9.1
Confluence Data Center - addressed in versions 7.19.22, 8.5.9, 8.9.1
Confluence Data Center - addressed in versions 7.19.22, 8.5.9, 8.9.1
Links to Public Exploits and PoC-codes
- Exploit #10951 - cve-2024-21683-rce (December 6, 2024)
- Exploit #10194 - Atlassian Confluence Administrator Code Macro Remote Code Execution (July 11, 2024)
- Exploit #9944 - CVE-2024-21683 (June 7, 2024)
- Exploit #9893 - -CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server (May 31, 2024)
- Exploit #9875 - CVE-2024-21683-RCE (May 31, 2024)