Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
6 years ago

CVE-2019-3396: Vulnerability in Atlassian Confluence Widget...

CVE-2019-3396: Vulnerability in Atlassian Confluence Widget Connector Exploited In The Wild

In recent weeks, attackers have been probing for and exploiting a vulnerability in Atlassian Confluence Widget Connector on vulnerable systems to install ransomware, DDoS botnets and cryptocurrency miners.

Atlassian published a Confluence Security Advisory on March 20, 2019 to announce fixes for two vulnerabilities, CVE-2019-3395 and CVE-2019-3396.

  1. CVE-2019-3395 is a critical server-side request forgery (SSRF) vulnerability in the WebDAV plugin in Confluence Server and Data Center versions released before June 18, 2018.
  2. CVE-2019-3396 is a critical server-side template injection vulnerability in Confluence Server and Data Center Widget Connector that could lead to path traversal and remote code execution.

For more details about this story, please visit our blog.

1 Reply

  • snarang's avatar
    snarang
    Product Team

    Update 4/30: A list of Nessus plugins to identify these vulnerabilities can be found here.