Description
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gmail SMTP Arbitrary File Disclosure (1.1.0)
WordPress Plugin WordPress OpenID Connect Client Cross-Site Scripting (2.1.4)
Oracle Database Server CVE-2014-4293 Vulnerability (CVE-2014-4293)
WordPress Plugin WP Easy Slideshow Multiple Cross-Site Request Forgery Vulnerabilities (1.0.3)