Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-83218

A user with read permissions to a Confluence page is able to upload attachments - CVE-2023-22504

    • 4.3
    • Medium
    • CVE-2023-22504

      Affected versions of Atlassian Confluence Server and Data Center allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

      The affected versions are before version 7.13.17, from version 7.14.0 before 7.19.9, and from version 7.20.0 before 8.2.2.

      This vulnerability was discovered by Rojan Rijal of the Tinder Security Engineering Team.

      Affected versions:

      • version < 7.13.17
      • 7.14.0 ≀ version < 7.19.9
      • 7.20.0 ≀ version < 8.2.2

      Fixed versions:

      • 7.13.17
      • 7.19.9
      • 8.2.2
      • 8.3.0

          Form Name

            [CONFSERVER-83218] A user with read permissions to a Confluence page is able to upload attachments - CVE-2023-22504

            AB added a comment -

            ddb136f454b4 Yes, it's reflected in the attachment's version history as per a normal update.

            AB added a comment - ddb136f454b4 Yes, it's reflected in the attachment's version history as per a normal update.

            Would it be reflected in the attachment's version history?

            Oleksiy Brushkovskyy added a comment - Would it be reflected in the attachment's version history?

            AB added a comment -

            50e16252c2f5 Yes, that's correct. I've updated the ticket description to confirm this.

            AB added a comment - 50e16252c2f5 Yes, that's correct. I've updated the ticket description to confirm this.

            William W added a comment -

            I assume because this is listed under Confluence "Server" it applies to both Data Center and Server? Can you please confirm?

            William W added a comment - I assume because this is listed under Confluence "Server" it applies to both Data Center and Server? Can you please confirm?

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 4.3 => Medium severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required Low
            User Interaction None

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality None
            Integrity Low
            Availability None

            https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

            Security Metrics Bot added a comment - This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 4.3 => Medium severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required Low User Interaction None Scope Metric Scope Unchanged Impact Metrics Confidentiality None Integrity Low Availability None https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

              ablack@atlassian.com AB
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: