IT

Tracker / CVE-2021-43940

CVE-2021-43940

High 7.8

Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

Affected products and versions

atlassian confluence_data_center · … → 7.4.10
atlassian confluence_data_center · 7.5.0 → 7.12.3
atlassian confluence_server · … → 7.4.10
atlassian confluence_server · 7.5.0 → 7.12.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References