LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-3396: Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-3396 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

CVE-2019-3396 is a server-side template injection vulnerability in Atlassian Confluence Server and Data Center. According to CISA, it may allow an attacker to achieve path traversal and remote code execution. It has been used in ransomware activity, so unpatched instances remain a high-priority risk for IT and security teams.

Defenders should treat this as a serious remote code execution path on a widely deployed collaboration platform and confirm all version and fix details directly against the vendor advisory.

How it works

The weakness is tracked as CWE-22 (path traversal) in the context of a server-side template injection flaw. In products of this class, user-controlled input reaches a template engine without proper sanitization. An attacker who can supply crafted template expressions may cause the server to resolve unintended paths or evaluate code in the application’s context.

Successful abuse can lead to reading files outside intended directories and, as described by CISA, remote code execution on the Confluence host. Exact request patterns, parameters, and exploit mechanics are not detailed here; teams must rely on the vendor advisory and their own testing rather than public proof-of-concept material.

Am I affected? How to find it in your systems

Atlassian Confluence Server and Data Center typically run as internal or externally reachable web applications used for wikis, documentation, and team collaboration. They are often deployed on Linux or Windows servers, sometimes behind reverse proxies, and may be exposed to the internet for remote access.

Inventory steps:

If you cannot determine the version or exposure with certainty, assume the instance needs review until confirmed otherwise.

How to remediate

Patch first. Apply the updates published by Atlassian for Confluence Server and Data Center exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

After patching:

If you can't patch immediately

Implement compensating controls until the vendor update can be applied:

These measures reduce risk but do not replace the patch.

If your data may have been exposed

Actively exploited vulnerabilities of this type, including those with known ransomware use, frequently lead to full host compromise, data theft, and follow-on encryption or extortion. If you have evidence of exploitation or cannot rule it out, follow your incident-response process: isolate affected systems, preserve logs, rotate credentials, and assess what data the Confluence instance could access.

You can also run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information associated with your organization have appeared in prior breaches, then force password resets and enable multi-factor authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAtlassian · Confluence Server and Data Server
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities