CVE-2024-21674

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 16, 2024
Updated: Jan 22, 2024
CWE ID 94

Summary

CVE-2024-21674 is a high severity Remote Code Execution (RCE) vulnerability affecting Confluence Data Center and Server versions 7.13.0 and above. This issue, with a CVSS score of 8.6, allows unauthenticated attackers to expose assets in vulnerable environments, posing a significant risk to confidentiality. Atlassian advises upgrading to the latest version of Confluence to mitigate this vulnerability. For those unable to upgrade immediately, specific fixed versions are recommended: Confluence Data Center and Server 7.19 users should upgrade to 7.19.18 or later, while 8.5 and 8.7 users should upgrade to 8.5.5 or later and 8.7.2 or later, respectively. The release notes and the latest version download can be found on Atlassian's website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Confluence Server
  • Confluence Data Center

Affected Vendors

  • Atlassian Corporation Pty Ltd.