Atlassian Confluence Server from version 6.12.0 (or earlier), and before version 6.13.1, or before version 6.14.0 allows an authenticated user to download a deleted page via the word export feature.

            [CONFSERVER-57814] Download a deleted page via word export - CVE-2018-20237

            set-jac-bot made changes -
            Usman Khalid (Inactive) made changes -
            Labels Original: advisory advisory-released bugbounty cve-2018-20237 cvss-low enterprise-backlog idor scale-team security New: advisory advisory-released bugbounty cve-2018-20237 cvss-low idor scale-team security
            Usman Khalid (Inactive) made changes -
            Labels Original: advisory advisory-released bugbounty cve-2018-20237 cvss-low enterprise-backlog idor security New: advisory advisory-released bugbounty cve-2018-20237 cvss-low enterprise-backlog idor scale-team security
            David Black made changes -
            Summary Original: Download a deleted page via word export New: Download a deleted page via word export - CVE-2018-20237
            Matt Hart (Inactive) made changes -
            Labels Original: advisory advisory-to-release bugbounty cve-2018-20237 cvss-low enterprise-backlog idor security New: advisory advisory-released bugbounty cve-2018-20237 cvss-low enterprise-backlog idor security
            Matt Hart (Inactive) made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            g made changes -
            Security Original: Atlassian Staff [ 10750 ] New: Reporter and Atlassian Staff [ 10751 ]
            g made changes -
            Reporter Original: Security Metrics Bot [ security-metrics-bot ] New: CERT-XLM [ 2ab2b2ee052a ]
            Matt Hart (Inactive) made changes -
            Labels Original: advisory advisory-to-release bugbounty cvss-low enterprise-backlog idor security New: advisory advisory-to-release bugbounty cve-2018-20237 cvss-low enterprise-backlog idor security
            Matt Hart (Inactive) made changes -
            Description Original: Component in Atlassian Confluence Server from version 6.12.0 before version 6.13.1 and before version 6.14.0 allows an authenticated user to download a deleted page via the word export feature. New: Atlassian Confluence Server from version 6.12.0 (or earlier), and before version 6.13.1, or before version 6.14.0 allows an authenticated user to download a deleted page via the word export feature.

              mhart@atlassian.com Matt Hart (Inactive)
              2ab2b2ee052a CERT-XLM
              Affected customers:
              0 This affects my team
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: