S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2019-3396 Scanner

CVE-2019-3396 scanner - Remote Code Execution (RCE) vulnerability in Atlassian Confluence Server

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-3396
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Confluence Serverby Atlassian
AFFECTED< 6.6.12SAFE ✓≥ 6.6.12
Updated Aug 21, 2026View on NVD →
Detail

Atlassian Confluence Server is a web-based collaboration and enterprise wiki software that helps teams to work together and share knowledge in a single location. The software provides an easy-to-use interface for creating, organizing, and sharing information with the team members. Users can use it to create pages, blogs, and information-rich documentations. It's commonly used by businesses and organizations to streamline their workflow, facilitate communication, and improve team collaboration.

The CVE-2019-3396 vulnerability discovered in the Atlassian Confluence Server is a critical path traversal vulnerability that allows a remote attacker to execute code on the server. The Widget Connector macro in Atlassian Confluence Server is vulnerable to this security flaw from version 6.7.0 through 6.14.2. If exploited, the vulnerability would allow an attacker to achieve server-side template injection and execute arbitrary code on the affected server.

This vulnerability, if exploited, could allow an attacker to gain access to sensitive information, modify or delete files, and take full control of the server. This poses a significant threat to organizations as it can lead to the theft of customer data or financial information. It can also result in a loss of reputation and trust.

Finally, thanks to the pro features of the S4E platform, you can easily and quickly learn about vulnerabilities in your digital assets. The platform provides comprehensive vulnerability management capabilities, and its advanced scanning techniques can help to detect even the most obscure security flaws. With the S4E platform, you can ensure that your digital assets are secure and that your organization's data remains protected.

 

REFERENCES

Solution Advice

To protect your organization against this vulnerability, you should ensure that the Atlassian Confluence Server software is updated to the latest version. Additionally, you can follow these precautions:

  • Implement strict access controls: Ensure that only authorized personnel can access the server. Use two-factor authentication and limit the number of users who have admin privileges.
  • Monitor server logs: Keep an eye on the logs for any suspicious activities or unusual traffic.
  • Use a web application firewall: A web application firewall will help to prevent attacks by filtering out malicious traffic.
  • Disable unneeded plugins and macros: Disable any functionality that your team is not using or needs.
  • Conduct regular vulnerability assessments: Regular vulnerability assessments can help to identify any potential weaknesses in the system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-3396 scanner - Remote Code Execution (RCE) vulnerability in Atlassian Confluence Server | S4E