CVE-2020-29448

MEDIUM

Confluence Server/Data Center <6.13.18-7.4.6-7.8.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

References (1)

Core 1
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/CONFSERVER-60469

Scores

CVSS v3 5.3
EPSS 0.0063
EPSS Percentile 70.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (2)
atlassian/confluence_data_center < 6.13.18
atlassian/confluence_server < 6.13.18
Published Feb 22, 2021
Tracked Since Feb 18, 2026