
CVE-2021-39114
https://notcve.org/view.php?id=CVE-2021-39114
05 Apr 2022 — Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5. Las versiones afectadas de Atlassian Confluence Server y Data Center permiten a los usuarios con una cuenta válida en una ins... • https://jira.atlassian.com/browse/CONFSERVER-68844 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2021-43940
https://notcve.org/view.php?id=CVE-2021-43940
15 Feb 2022 — Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3. Las versiones afectadas de Atlassian Confluence Server y Data Center permiten a los atacantes locales autentificado... • https://jira.atlassian.com/browse/CONFSERVER-66550 • CWE-427: Uncontrolled Search Path Element •

CVE-2021-26084 – Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
https://notcve.org/view.php?id=CVE-2021-26084
30 Aug 2021 — In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5. En las versiones afectadas de Confluence Server y Data Center, se presenta una vulnerabilidad de inyección OGNL que permitiría a un usuar... • https://packetstorm.news/files/id/164122 • CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') •

CVE-2021-26085 – Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability
https://notcve.org/view.php?id=CVE-2021-26085
03 Aug 2021 — Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3. Las versiones afectadas de Atlassian Confluence Server permiten a los atacantes remotos visualizar recursos restringidos por medio de una vulnerabilidad de lectura arbitraria de archivos de autorización previa en el endpoint /s/. Las versio... • https://packetstorm.news/files/id/164401 • CWE-425: Direct Request ('Forced Browsing') •

CVE-2020-29444
https://notcve.org/view.php?id=CVE-2020-29444
07 May 2021 — Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters. Unas versiones afectadas de Team Calendar en Confluence Server anteriores a 7.11.0, permiten a atacantes inyectar HTML o Javascript arbitrario por medio de una vulnerabilidad de tipo Cross Site Scripting en parámetros de configuración global de administración • https://jira.atlassian.com/browse/CONFSERVER-61266 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-29448
https://notcve.org/view.php?id=CVE-2020-29448
18 Feb 2021 — The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check. La clase ConfluenceResourceDownloadRewriteRule en Confluence Server y Confluence Data Center versiones anteriores a 6.13.18, desde 6.14.0 anteriores a 7.4.6 y desde 7.5.0 anteriores a 7.8.3, permit... • https://jira.atlassian.com/browse/CONFSERVER-60469 •

CVE-2020-14175
https://notcve.org/view.php?id=CVE-2020-14175
24 Jul 2020 — Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before 7.5.2. Las versiones afectadas de Atlassian Confluence Server y Data Center, permiten a atacantes remotos inyectar HTML o JavaScript arbitrario por medio de una vulnerabilidad de tipo Cross-Site Scripting (XSS) en los parámetros de ma... • https://jira.atlassian.com/browse/CONFSERVER-60102 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •