Details
-
Bug
-
Resolution: Fixed
-
High
-
2.7, 2.8, 2.9, 2.10, 3.0, 3.1, 3.2, 3.3, 3.4
Description
We have identified and fixed a vulnerability in the Remote API which affects Confluence instances, including publicly available instances. The Remote API allows an attacker to escalate user privileges, excluding the level of system administrator privileges.
This issue is reported in our security advisory on this page:
http://confluence.atlassian.com/x/FAZ7DQ