CVE-2023-22503

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/05/2023
Last modified:
01/10/2024

Description

Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.<br /> <br /> This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.<br /> <br /> The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* 7.13.15 (excluding)
cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* 7.14.0 (including) 7.19.7 (excluding)
cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:* 7.20.0 (including) 8.2.0 (excluding)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* 7.13.15 (excluding)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* 7.14.0 (including) 7.19.7 (excluding)
cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:* 7.20.0 (including) 8.2.0 (excluding)


References to Advisories, Solutions, and Tools