In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
History

Tue, 04 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2021-11-03'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2025-02-04T14:48:39.312Z

Reserved: 2021-01-25T00:00:00.000Z

Link: CVE-2021-26084

cve-icon Vulnrichment

Updated: 2024-08-03T20:19:19.592Z

cve-icon NVD

Status : Analyzed

Published: 2021-08-30T07:15:06.587

Modified: 2025-02-10T18:02:37.233

Link: CVE-2021-26084

cve-icon Redhat

No data.