{"api_version":"1","generated_at":"2026-07-23T19:12:57+00:00","cve":"CVE-2023-22503","urls":{"html":"https://cve.report/CVE-2023-22503","api":"https://cve.report/api/cve/CVE-2023-22503.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-22503","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-22503"},"summary":{"title":"CVE-2023-22503","description":"Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.\r\n\r\nThis vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.\r\n\r\nThe affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0.","state":"PUBLIC","assigner":"security@atlassian.com","published_at":"2023-05-01 17:15:00","updated_at":"2023-05-09 16:24:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://jira.atlassian.com/browse/CONFSERVER-82403","name":"https://jira.atlassian.com/browse/CONFSERVER-82403","refsource":"MISC","tags":[],"title":"[CONFSERVER-82403] Information disclosure of names of attachments and labels in a private Confluence space - Create and track feature requests for Atlassian products.","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-22503","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-22503","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"22503","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"confluence_data_center","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"22503","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"confluence_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-22503","qid":"730793","title":"Atlassian Confluence Server and Confluence Data Center Information Disclosure Vulnerability (CONFSERVER-82403)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-22503","ASSIGNER":"security@atlassian.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature.\r\n\r\nThis vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team.\r\n\r\nThe affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information Disclosure"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Atlassian","product":{"product_data":[{"product_name":"Confluence Data Center","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"versions":[{"version":"< 7.20.2","status":"unaffected"},{"version":">= 7.20.2","status":"affected"},{"version":">= 7.13.5","status":"unaffected"},{"version":">= 7.19.7","status":"unaffected"},{"version":">= 8.20.0","status":"unaffected"}]}}]}},{"product_name":"Confluence Server","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"versions":[{"version":"< 7.20.2","status":"unaffected"},{"version":">= 7.20.2","status":"affected"},{"version":">= 7.13.5","status":"unaffected"},{"version":">= 7.19.7","status":"unaffected"},{"version":">= 8.20.0","status":"unaffected"}]}}]}}]}}]}},"references":{"reference_data":[{"url":"https://jira.atlassian.com/browse/CONFSERVER-82403","refsource":"MISC","name":"https://jira.atlassian.com/browse/CONFSERVER-82403"}]},"credits":[{"lang":"en","value":"This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team."}],"impact":{"cvss":[{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM"}]}},"nvd":{"publishedDate":"2023-05-01 17:15:00","lastModifiedDate":"2023-05-09 16:24:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*","versionEndExcluding":"7.13.15","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*","versionStartIncluding":"7.14.0","versionEndExcluding":"7.19.7","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*","versionStartIncluding":"7.20.0","versionEndExcluding":"8.2.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*","versionStartIncluding":"7.20.0","versionEndExcluding":"8.2.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*","versionStartIncluding":"7.14.0","versionEndExcluding":"7.19.7","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:confluence_server:*:*:*:*:*:*:*:*","versionEndExcluding":"7.13.15","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}