This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives). This vulnerability was reported via our Bug Bounty program.
History

Thu, 13 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Atlassian
Atlassian confluence Data Center
Atlassian confluence Server
Weaknesses CWE-79
CPEs cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*
Vendors & Products Atlassian
Atlassian confluence Data Center
Atlassian confluence Server
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2024-08-07T14:53:10.328Z

Reserved: 2024-01-01T00:05:33.847Z

Link: CVE-2024-21686

cve-icon Vulnrichment

Updated: 2024-08-01T22:27:36.033Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-16T20:15:02.900

Modified: 2025-02-13T17:09:31.977

Link: CVE-2024-21686

cve-icon Redhat

No data.