Description
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.
Remediation
References
Related Vulnerabilities
MySQL CVE-2016-0662 Vulnerability (CVE-2016-0662)
TwistedHTTP Request Splitting Vulnerability (CVE-2020-10109)
WordPress Plugin Login rebuilder Cross-Site Request Forgery (1.1.3)
Jenkins Improper Input Validation Vulnerability (CVE-2016-0789)
PHP Missing Release of Resource after Effective Lifetime Vulnerability (CVE-2010-4657)