vulnerability

Atlassian Confluence: Unrestricted Upload of File with Dangerous Type (CVE-2023-22504)

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:N/I:C/A:N)
Published
05/25/2023
Added
06/26/2024
Modified
01/28/2025

Description

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

Solution(s)

atlassian-confluence-upgrade-7_13_17atlassian-confluence-upgrade-7_19_9atlassian-confluence-upgrade-8_2_2atlassian-confluence-upgrade-8_3_0
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.