Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CVE-2025-24813 - Confluence Apache affected on the data center shipment.

RA
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 18, 2025

Can advise if this CVE is affected on the Confluence 9.2.1 version

2 answers

1 vote
Rilwan Ahmed
Community Champion
June 18, 2025

Hi @RA ,

Welcome to the community !!

CVE-2025-24813 does not appear to be a publicly disclosed vulnerability in Atlassian list. 

However, Confluence Data Center 9.2.1 (LTS) is affected by other known vulnerabilities:

  • CVE-2025-31650: This high-severity vulnerability, identified in May 2025, can lead to a Denial of Service (DoS) due to a memory leak in Apache Tomcat. It affects Confluence Data Center versions 7.13.0 through 9.4.0. 

  • CVE-2024-50379 and CVE-2024-56337: Both are critical Remote Code Execution (RCE) vulnerabilities in the Apache Tomcat Catalina component, impacting Confluence Data Center versions up to 9.2.1.

For the most current information, considering checking  https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html

If you cannot upgrade confluence, you can try upgrading only the tomcat version. I recommend you try this is test server, take backup and then do it in production instance. 
https://support.atlassian.com/confluence/kb/how-to-upgrade-the-tomcat-container-for-confluence/

0 votes
Marc - Devoteam
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 18, 2025

Hi @RA 

Welcome to the community.

Looking at the impacted tomcat from 9.0.1. to 9.0.99 and Confluence has version 9.0.98 bundled in the package, I suspect yes it will be impacted.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
ENTERPRISE
TAGS
AUG Leaders

Atlassian Community Events