Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-61266

Persistent XSS through Team Calendar in Confluence Server - CVE-2020-29444

    • 5.4
    • Medium
    • CVE-2020-29444

      Affected versions of Team Calendar in Confluence Server allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting vulnerability in admin global setting parameters.

      Affected versions:

      • < 7.11.0

      Fixed version:

      • 7.11.0

       

      This vulnerability is attributed to Stefano Castilletti, a security researcher from Apple.

            [CONFSERVER-61266] Persistent XSS through Team Calendar in Confluence Server - CVE-2020-29444

            Is this fixed by 7.4.17?

             

            simon.r.martin added a comment - Is this fixed by 7.4.17?  

            Sreekanth added a comment -

            We recently upgraded Confluence to version 7.13.0 as proposed in the Atlassian Security Advisory. But our scans still shows 1 vulnerability which will be fixed when the Instance is upgraded to 7.11.0!? Below is the solution proposed from our scans.
             

            Published: 2021-05-07T00:00:00Z

            Last updated: 2021-06-03T09:10:26.000Z

            Atlassian Confluence

            Upgrade Atlassian Confluence to version 7.11.0

            Upgrade Atlassian Confluence to version 7.11.0 from https://www.atlassian.com/software/confluence/download-archives

            Pls suggest!

             

            Sreekanth added a comment - We recently upgraded Confluence to version 7.13.0 as proposed in the Atlassian Security Advisory. But our scans still shows 1 vulnerability which will be fixed when the Instance is upgraded to 7.11.0!? Below is the solution proposed from our scans.   Published: 2021-05-07T00:00:00Z Last updated: 2021-06-03T09:10:26.000Z Atlassian Confluence Upgrade Atlassian Confluence to version 7.11.0 Upgrade Atlassian Confluence to version 7.11.0 from https://www.atlassian.com/software/confluence/download-archives Pls suggest!  

            Igor M. added a comment - - edited

            ganga.bopaiah eugen.zwinger746948495 TC version TC-6.1.8, TC-7.0.7 and latter contain the patch, if you upgrade Team Calendars plugin from the marketplace, you do not need to upgrade Confluence to get the fix. Above version of Confluence refers to bundled version of TC that comes with Confluence.

            Igor M. added a comment - - edited ganga.bopaiah eugen.zwinger746948495 TC version TC-6.1.8, TC-7.0.7 and latter contain the patch, if you upgrade Team Calendars plugin from the marketplace, you do not need to upgrade Confluence to get the fix. Above version of Confluence refers to bundled version of TC that comes with Confluence.

            Is the 7.4.4 LTS Version of Confluence also affected by this vulnerability?

            Ganga Bopaiah added a comment - Is the 7.4.4 LTS Version of Confluence also affected by this vulnerability?

            Is also the current LTS Version of Confluence affected by this vulnerability?

            Eugen Zwinger [demicon] added a comment - Is also the current LTS Version of Confluence affected by this vulnerability?

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 5.4 => Medium severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required Low
            User Interaction None

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality Low
            Integrity Low
            Availability None

            https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

            David Black added a comment - This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 5.4 => Medium severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required Low User Interaction None Scope Metric Scope Unchanged Impact Metrics Confidentiality Low Integrity Low Availability None https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: