QID 10501
Date Published: 2021-04-01
QID 10501: Atlassian Confluence Cross-Site Scripting Vulnerability (CONFSERVER-61622)
Confluence is team collaboration software written in Java.
Affected Versions:
Atlassian Confluence before version 7.4.8
QID Detection Logic:
This unauthenticated QID detects vulnerable Atlassian Confluence versions by making GET request to login.action page and parsing information exposed in ajs-version-number or footer-build-information HTML entities.
Allow a remote attacker to inject arbitrary Javascript into the context of the application.
Solution
Customers are advised to refer to upgrade to Atlassian Confluence 7.8.0, 6.13.20, 7.4.8 or later versions to remediate this vulnerability.
Vendor References
- CONFSERVER-61622 -
jira.atlassian.com/browse/CONFSERVER-61622
CVEs related to QID 10501
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CONFSERVER-61622 |
|