CVE-2019-3394 is a local file disclosure vulnerability affecting Atlassian Confluence Server and Data Center versions 6.1.0 through 6.15.7. An authenticated attacker with page editing permissions can exploit this flaw during page export to read arbitrary files within the /confluence/WEB-INF directory, potentially exposing sensitive configuration files and credentials like LDAP details. The vulnerability carries a high CVSS score of 8.8, indicating a network-exploitable issue with low attack complexity, requiring only low privileges, and leading to high confidentiality, integrity, and availability impacts. Its EPSS score of 0.6188 and FAUCET Risk Score of 98/100 highlight its significant potential for exploitation. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion or media coverage has been identified for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.0, < 6.6.16CPE matchmatch criteria | cpe:2.3:a:atlassian:confluence:*:*:*:*:*:*:*:* | ||
>= 6.7.0, < 6.13.7CPE matchmatch criteria | cpe:2.3:a:atlassian:confluence:*:*:*:*:*:*:*:* | ||
>= 6.14.0, < 6.15.8CPE matchmatch criteria | cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* | ||
< 6.13.7CPE match | cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* | ||
< 6.15.8CPE match | cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.