Vulnerability record · CVE-2019-3398 · published 18 April 2019
CVE-2019-3398: Atlassian Confluence Server path traversal in downloadallattachments
Atlassian · Confluence Server
Confluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachments, create spaces, or hold space Admin rights can write files to arbitrary locations, which can lead to remote code execution. It matters because the required privilege is common in normal Confluence use, and the flaw is listed in CISA KEV with a very high EPSS score.
Description
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows authenticated remote code execution, is listed in CISA KEV, and has an EPSS probability above 0.96, so it is being actively exploited.
What it is
Confluence Server and Data Center contain a path traversal flaw in the downloadallattachments resource. An attacker with permission to add attachments, create spaces, or hold space Admin rights can write files to arbitrary locations, which can lead to remote code execution. It matters because the required privilege is common in normal Confluence use, and the flaw is listed in CISA KEV with a very high EPSS score.
Impact
An attacker gains arbitrary file write on the Confluence host, which can be leveraged to execute code and take over the server. This can expose or destroy all content and credentials the instance holds.
Attack surface
Reachable over the network through the Confluence web interface; no user interaction is required, but the attacker must hold an authenticated account with attachment, space creation, or space Admin permissions.
Exploitation
CVE-2019-3398 is in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.96837 (99.885th percentile), indicating active exploitation. Public exploit references exist, though no ransomware group is documented as using it.
What to do
- Upgrade Confluence Server and Data Center to a fixed release: 6.6.13, 6.12.4, 6.13.4, 6.14.3, or 6.15.2 and later.
- If immediate patching is not possible, restrict who can add attachments, create spaces, or hold space Admin rights.
- Limit network exposure of Confluence to trusted users and networks.
- Review and remove unnecessary space Admin and attachment permissions from untrusted accounts.
- Monitor vendor advisories for any further guidance on this issue.
Detection
- Review Confluence access logs for requests to the downloadallattachments resource with traversal sequences such as ../ or encoded variants.
- Alert on file writes or new files appearing in web-accessible or unexpected directories on the Confluence host.
- Monitor for unexpected child processes spawned by the Confluence Java process.
- Audit accounts granted attachment, space creation, or space Admin permissions for unexpected changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-3398 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Atlassian Confluence Server and Data Center Path Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-3398 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-3398), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.