Atlassian Confluence High-Severity Bug Allows Code Execution
ID: 04699615-a3c1-5c5f-99d6-daf4d116288e
STIX ID: report--04699615-a3c1-5c5f-99d6-daf4d116288e
Feed Name: Dark Reading
Threat Score
SonicWall Capture Labs discovered CVE-2024-21683, a high-severity (CVSS 8.3) remote code execution vulnerability in Atlassian Confluence Data Center and Server. An authenticated attacker with permission to add macro languages can upload a forged JavaScript language file via Configure Code Macro > Add a new language to execute arbitrary code. PoC exploit code and IoCs are available, and SonicWall published IPS signatures and recommends upgrading to the latest Confluence versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
