QID 730338

Date Published: 2022-02-02

QID 730338: Atlassian Confluence Server Code Injection Vulnerability (CONFSERVER-74534)

Confluence is team collaboration software written in Java.

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint.

Affected Versions:
Atlassian Confluence Server versions prior to 7.4.13.
Atlassian Confluence Server versions 7.5.0 and 7.12.5 (inclusive).
Atlassian Confluence Server versions prior to 7.13.2
Atlassian Confluence Server versions 7.14.0 QID Detection Logic:
This unauthenticated QID detects vulnerable Atlassian Confluence versions by making GET request to login.action page and parsing information exposed in ajs-version-number or footer-build-information HTML entities.

Unicode bidirectional override characters and can allow malicious code to be hidden.

  • CVSS V3 rated as Critical - 8.3 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Vendor has released patch, for more information please refer to CONFSERVER-74534
    Vendor References

    CVEs related to QID 730338

    Software Advisories
    Advisory ID Software Component Link
    CONFSERVER-74534 URL Logo jira.atlassian.com/browse/CONFSERVER-74534