jira.atlassian.com
https://jira.atlassian.com/browse/CONFSERVER-83218 CVE-2023-22504
MEDIUM
Record summary
CVE-2023-22504 has a selected CVSS score of 6.5 (medium).
Description
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 1, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Confluence Data CenterBrowse Atlassian / Confluence Data Center | CVE List | < 1.1.2 | unaffected |
| >= 1.1.2 | affected | ||
| >= 7.14.0 | affected | ||
| >= 7.20.0 | affected | ||
| >= 7.13.7 | unaffected | ||
| >= 7.19.9 | unaffected | ||
| >= 8.2.2 | unaffected | ||
| >= 8.3.0 | unaffected | ||
Confluence ServerBrowse Atlassian / Confluence Server | CVE List | < 1.1.2 | unaffected |
| >= 1.1.2 | affected | ||
| >= 7.14.0 | affected | ||
| >= 7.20.0 | affected | ||
| >= 7.13.7 | unaffected | ||
| >= 7.19.9 | unaffected | ||
| >= 8.2.2 | unaffected | ||
| >= 8.3.0 | unaffected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-22504