Vulnerability record · CVE-2024-21683 · published 21 May 2024
CVE-2024-21683: Atlassian Confluence Data Center and Server code injection RCE
Atlassian · Confluence Data Center
Confluence Data Center and Server contain a code injection flaw introduced in version 5.2 that allows an authenticated attacker to execute arbitrary code. The vulnerability has a CVSS score of 8.8 and requires no user interaction, making it a serious risk for exposed instances.
Description
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes https://confluence.atlassian.com/doc/confluence-release-notes-327.html You can download the latest version of Confluence Data Center and Server from the download center https://www.atlassian.com/software/confluence/download-archives. This vulnerability was found internally.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS score of 8.8 and very high EPSS probability indicate a severe, likely exploitable vulnerability, though it requires authentication.
What it is
Confluence Data Center and Server contain a code injection flaw introduced in version 5.2 that allows an authenticated attacker to execute arbitrary code. The vulnerability has a CVSS score of 8.8 and requires no user interaction, making it a serious risk for exposed instances.
Impact
An authenticated attacker can execute arbitrary code with high impact to confidentiality, integrity, and availability of the Confluence instance. This could lead to full compromise of the application and its data.
Attack surface
The flaw is reachable over the network (AV:N) with low attack complexity (AC:L) and requires low privileges (PR:L) but no user interaction (UI:N). An attacker must have a valid account on the Confluence instance.
Exploitation
The vulnerability is not listed in CISA KEV, but EPSS indicates a very high probability of exploitation (0.88267, 99.76th percentile). No public exploit references are provided in the record.
What to do
- Upgrade Confluence Data Center and Server to the latest version or a specified supported fixed version as per Atlassian's advisory.
- If immediate patching is not possible, restrict network access to Confluence instances to trusted users only.
- Enforce strong authentication and least privilege for Confluence accounts to limit the impact of an authenticated attack.
- Monitor Atlassian's release notes and security advisories for further updates.
Detection
- Monitor Confluence application logs for unexpected code execution or suspicious administrative actions.
- Use network detection to identify unusual outbound connections from Confluence servers that could indicate command and control or data exfiltration.
- Audit user accounts for unauthorized privilege escalation or creation of new administrative users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://confluence.atlassian.com/pages/viewpage.action?pageId=1409286211 | Vendor Advisory |
| https://jira.atlassian.com/browse/CONFSERVER-95832 | Issue Tracking |
Track CVE-2024-21683 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-21683), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.