vulnerability
Atlassian Confluence: Unrestricted Upload of File with Dangerous Type (CVE-2023-22504)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:S/C:N/I:C/A:N) | May 25, 2023 | Jun 26, 2024 | Jan 28, 2025 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:N/I:C/A:N)
Published
May 25, 2023
Added
Jun 26, 2024
Modified
Jan 28, 2025
Description
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
Solutions
atlassian-confluence-upgrade-7_13_17atlassian-confluence-upgrade-7_19_9atlassian-confluence-upgrade-8_2_2atlassian-confluence-upgrade-8_3_0
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.