We have identified and fixed a vulnerability in the Remote API which affects Confluence instances, including publicly available instances. The Remote API allows an attacker to escalate user privileges, excluding the level of system administrator privileges.

      This issue is reported in our security advisory on this page:
      http://confluence.atlassian.com/x/FAZ7DQ

            [CONFSERVER-21162] Security Vulnerability in Confluence Remote API

              don.willis@atlassian.com Don Willis
              shawse Sally Hawse [Atlassian]
              Affected customers:
              0 This affects my team
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: