RULE(RULE ID:338050)

Rule General Information
Release Date: 2024-05-29
Rule Name: Confluence Data Center and Server Remote Code Execution Vulnerability (CVE-2024-21683)
Severity:
CVE ID:
Rule Protection Details
Description: Atlassian Confluence is a suite of professional enterprise knowledge management and collaboration software from Atlassian Australia, which can also be used to build enterprise WiKi. Atlassian Confluence Data Center and Server has a remote code execution vulnerability that allows an authenticated attacker to execute arbitrary code.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://confluence.atlassian.com/pages/viewpage.action?pageId=1387867145
https://jira.atlassian.com/browse/CONFSERVER-95832
Solutions
Refer to the announcement or patch by the vendor: https://confluence.atlassian.com/pages/viewpage.action