CVE-2021-26072

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
01/04/2021
Last modified:
27/07/2022

Description

The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* 5.8.6 (excluding)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* 5.8.6 (excluding)


References to Advisories, Solutions, and Tools