CVE-2020-24898

The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.6 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
mitreCNA
7.6 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AC:L/AV:N/A:L/C:H/I:L/PR:L/S:U/UI:N
CVEADP
---
---