Looking for the vulnerability index of Invicti's legacy products?
Unauthenticated OGNL injection in Confluence Server and Data Center - Vulnerability Database

Unauthenticated OGNL injection in Confluence Server and Data Center

Description

An OGNL injection vulnerability exists that allows an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.

Affected versions:

version < 6.13.23
6.14.0 = version < 7.4.11
7.5.0 = version < 7.11.5
7.12.0 = version < 7.12.5

Remediation

Upgrade to the latest version of Confluence. <br/> Fixed versions:<br/> <br/> <li>6.13.23</li> <li>7.4.11</li> <li>7.11.6</li> <li>7.12.5</li> <li>7.13.0</li>

Related Vulnerabilities