CVE-2023-22503
Summary
| CVE | CVE-2023-22503 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-01 17:15:00 UTC |
| Updated | 2023-05-09 16:24:00 UTC |
| Description | Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team. The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Confluence Data Center | All | All | All | All |
| Application | Atlassian | Confluence Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [CONFSERVER-82403] Information disclosure of names of attachments and labels in a private Confluence space - Create and track feature requests for Atlassian products. | MISC | jira.atlassian.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730793 Atlassian Confluence Server and Confluence Data Center Information Disclosure Vulnerability (CONFSERVER-82403)