CVE-2017-9505

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/06/2017
Last modified:
20/04/2025

Description

Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:confluence:*:*:*:*:*:*:*:* 4.3 (including) 6.2.1 (excluding)