CVE-2023-22504
25.05.2023, 14:15
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.Enginsight
Vendor | Product | Version |
---|---|---|
atlassian | confluence_server | 𝑥 < 7.13.17 |
atlassian | confluence_server | 7.14.0 ≤ 𝑥 < 7.19.9 |
atlassian | confluence_server | 7.20.0 ≤ 𝑥 < 8.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration