-
Bug
-
Resolution: Fixed
-
Low
-
6.12.0
-
Severity 3 - Minor
-
Atlassian Confluence Server from version 6.12.0 (or earlier), and before version 6.13.1, or before version 6.14.0 allows an authenticated user to download a deleted page via the word export feature.
[CONFSERVER-57814] Download a deleted page via word export - CVE-2018-20237
Fixed in Enterprise Release/s | New: [Download 6.13|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html] |
Labels | Original: advisory advisory-released bugbounty cve-2018-20237 cvss-low enterprise-backlog idor scale-team security | New: advisory advisory-released bugbounty cve-2018-20237 cvss-low idor scale-team security |
Labels | Original: advisory advisory-released bugbounty cve-2018-20237 cvss-low enterprise-backlog idor security | New: advisory advisory-released bugbounty cve-2018-20237 cvss-low enterprise-backlog idor scale-team security |
Summary | Original: Download a deleted page via word export | New: Download a deleted page via word export - CVE-2018-20237 |
Labels | Original: advisory advisory-to-release bugbounty cve-2018-20237 cvss-low enterprise-backlog idor security | New: advisory advisory-released bugbounty cve-2018-20237 cvss-low enterprise-backlog idor security |
Security | Original: Reporter and Atlassian Staff [ 10751 ] |
Security | Original: Atlassian Staff [ 10750 ] | New: Reporter and Atlassian Staff [ 10751 ] |
Reporter | Original: Security Metrics Bot [ security-metrics-bot ] | New: CERT-XLM [ 2ab2b2ee052a ] |
Labels | Original: advisory advisory-to-release bugbounty cvss-low enterprise-backlog idor security | New: advisory advisory-to-release bugbounty cve-2018-20237 cvss-low enterprise-backlog idor security |
Description | Original: Component in Atlassian Confluence Server from version 6.12.0 before version 6.13.1 and before version 6.14.0 allows an authenticated user to download a deleted page via the word export feature. | New: Atlassian Confluence Server from version 6.12.0 (or earlier), and before version 6.13.1, or before version 6.14.0 allows an authenticated user to download a deleted page via the word export feature. |