-
Public Security Vulnerability
-
Resolution: Fixed
-
Low
-
7.4.6
-
None
-
4.3
-
Medium
-
CVE-2020-29445
Affected versions of Confluence Server allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.
Affected versions:
- < 7.11.0
Fixed versions:
- 7.11.0
- 7.4.8 (LTS)
This vulnerability is attributed to Stefano Castilletti, a security researcher at Apple.
[CONFSERVER-61453] Blind SSRF in Team Calendars REST API using location parameter - CVE-2020-29445
Remote Link | New: This issue links to "Page (Confluence)" [ 733360 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 647673 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 629054 ] |
CVE ID | New: CVE-2020-29445 |
Description |
Original:
Affected versions of Confluence Server allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.
Affected versions: * < 7.11.0 Fixed versions: * 7.11.0 This vulnerability is attributed to Stefano Castilletti, a security researcher at Apple. |
New:
Affected versions of Confluence Server allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.
Affected versions: * < 7.11.0 Fixed versions: * 7.11.0 * 7.4.8 (LTS) This vulnerability is attributed to Stefano Castilletti, a security researcher at Apple. |
Remote Link | Original: This issue links to "Page (Confluence)" [ 553511 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 553511 ] |
Fix Version/s | New: 7.4.8 [ 94601 ] |
Labels | Original: advisory advisory-to-release dont-import security | New: advisory advisory-released dont-import security |
Is it planed to include this bug fixes also into the current LTS Version?