CVE-2018-20237Resource Exposure in Atlassian Confluence Data Center

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 40.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateMay 13

Description

Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5atlassian/confluence_data_centerunspecified6.13.1
NVDatlassian/confluence_data_center6.13.26.14.0+1
CVEListV5atlassian/confluence_serverunspecified6.13.1
NVDatlassian/confluence_server6.13.26.14.0+1

🔴Vulnerability Details

2
GHSA
GHSA-6cff-mj8v-fvr9: Atlassian Confluence Server and Data Center before version 62022-05-13
CVEList
CVE-2018-20237: Atlassian Confluence Server and Data Center before version 62019-02-13
CVE-2018-20237 — Resource Exposure in Atlassian | cvebase