QID 730572

Date Published: 2022-07-21

QID 730572: Atlassian Confluence Server and Confluence Data Center Multiple Servlet Filter Vulnerabilities (CONFSERVER-79476)

Confluence is team collaboration software written in Java.



Affected version:
Confluence Server and Data Center versions
version prior to 7.4.17
7.13.0 prior to 7.13.7
7.14.0 prior to 7.14.3
7.15.0 prior to 7.15.2
7.16.0 prior to 7.15.4
7.17.0 prior to 7.17.4
7.18.0 are affected

QID Detection Logic:(Unauthenticated)
It checks for vulnerable versions of Atlassian Confluence Server.

Successful exploitation of this vulnerability could lead to a security breach or could affect confidentiality, integrity, and availability.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Customers are advised to refer to CONFSERVER-79476 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 730572

    Software Advisories
    Advisory ID Software Component Link
    CONFSERVER-79476 URL Logo jira.atlassian.com/browse/CONFSERVER-79476