In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published: 2022-06-03T21:51:57.134389Z

Updated: 2024-09-16T18:55:17.016Z

Reserved: 2022-02-25T00:00:00

Link: CVE-2022-26134

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-03T22:15:07.717

Modified: 2024-06-28T14:22:46.883

Link: CVE-2022-26134

cve-icon Redhat

No data.