Unauthenticated OGNL injection in Confluence Server and Data Center
Description
An OGNL injection vulnerability exists that allows an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.
Affected versions:
version < 6.13.23
6.14.0 = version < 7.4.11
7.5.0 = version < 7.11.5
7.12.0 = version < 7.12.5
Remediation
Upgrade to the latest version of Confluence. <br/> Fixed versions:<br/> <br/> <li>6.13.23</li> <li>7.4.11</li> <li>7.11.6</li> <li>7.12.5</li> <li>7.13.0</li>