Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hfhf-22gm-76w3

Опубликовано: 25 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

The affected versions are before version 7.19.9.

This vulnerability was discovered by Rojan Rijal of the Tinder Security Engineering Team.

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

The affected versions are before version 7.19.9.

This vulnerability was discovered by Rojan Rijal of the Tinder Security Engineering Team.

EPSS

Процентиль: 52%
0.0029
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

EPSS

Процентиль: 52%
0.0029
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-434