QID 730184

Date Published: 2021-09-15

QID 730184: Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability (CONFSERVER-67893)

Confluence is team collaboration software written in Java.

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint.

Affected Versions:
Atlassian Confluence Server versions prior to 7.4.10.
Atlassian Confluence Server versions 7.5.0-7.12.2.

QID Detection Logic:
This unauthenticated QID detects vulnerable Atlassian Confluence versions by making GET request to login.action page and parsing information exposed in ajs-version-number or footer-build-information HTML entities.

Successful exploitation of vulnerability may allow remote attackers to read sensitive files on server.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released patch, for more information please refer to CONFSERVER-67893
    Vendor References

    CVEs related to QID 730184

    Software Advisories
    Advisory ID Software Component Link
    CONFSERVER-67893 URL Logo jira.atlassian.com/browse/CONFSERVER-67893