Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-82403

Information disclosure of names of attachments and labels in a private Confluence space - CVE-2023-22503

    • 5.3
    • Medium
    • CVE-2023-22503

      Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.

      This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.

      The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.

      Affected versions:

      • version < 7.13.15
      • 7.14.0 ≀ version < 7.19.7
      • 7.20.0 ≀ version < 8.2.0

      Fixed versions:

      • 7.13.15
      • 7.19.7
      • 8.2.0

            [CONFSERVER-82403] Information disclosure of names of attachments and labels in a private Confluence space - CVE-2023-22503

            Austin added a comment -

            7.19.7 also appears to be unreleased (for us LTS folks).

            Austin added a comment - 7.19.7 also appears to be unreleased (for us LTS folks).

            so when is 8.2 released? kinda hard to upgrade to it atm

            Casper Hjorth Christensen added a comment - so when is 8.2 released? kinda hard to upgrade to it atm

            Amar Khot added a comment -

            Hi Team,

            Please provide clarity on if this vulnerability has an impact on any other Confluence LTS versions

            –

            Regards

            Amar Khot

            Amar Khot added a comment - Hi Team, Please provide clarity on if this vulnerability has an impact on any other Confluence LTS versions – Regards Amar Khot

            I think/hope there is something wrong with listed versions.

            The newest version is 8.1.0 as of 2023-02-22.

            Kristoffer Skude Jensen added a comment - I think/hope there is something wrong with listed versions. The newest version is 8.1.0 as of 2023-02-22.

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 5.3 => Medium severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required None
            User Interaction None

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality Low
            Integrity None
            Availability None

            https://asecurityteam.bitbucket.io/cvss_v3/?#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

            Security Metrics Bot added a comment - This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 5.3 => Medium severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required None User Interaction None Scope Metric Scope Unchanged Impact Metrics Confidentiality Low Integrity None Availability None https://asecurityteam.bitbucket.io/cvss_v3/?#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              17 Start watching this issue

                Created:
                Updated:
                Resolved: