CVE-2021-26085
03.08.2021, 00:15
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
Vendor | Product | Version |
---|---|---|
atlassian | confluence_data_center | 𝑥 < 7.4.10 |
atlassian | confluence_data_center | 7.5.0 ≤ 𝑥 < 7.12.3 |
atlassian | confluence_server | 𝑥 < 7.4.10 |
atlassian | confluence_server | 7.5.0 ≤ 𝑥 < 7.12.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References