HIGH · CVSS 8.3

CVE-2024-21683 — Confluence RCE

Authenticated RCE in Confluence — admin can execute arbitrary code via 'New Macro Language' configuration.

Affects
  • Confluence Data Center + Server pre-patch

What an attacker does

Authenticated admin uploads malicious macro language definition; server executes during page render.

How to detect

Confluence version + admin-account audit

How to fix

Upgrade to patched Confluence

Securie findinghigh · CVSS 8.3
CVE-2024-21683

How Securie catches CVE-2024-21683

Securie's static-rules + identity-gov scan installed Confluence + admin-account count.

Scan my repo for CVE-2024-21683Securie scans every PR · free during early access

References